SUSE-SU-2022:2568-1
Dashboard / Vulnerabilities / SUSE-SU-2022:2568-1
SUSE-SU-2022:2568-1
Summary: Security update for SUSE Manager Server 4.2
Details: This update fixes the following issues: apache-commons-csv: - Fix the URL for the package - Declare the LICENSE file as license and not doc apache-commons-math3: - Fix the URL for the package - Declare the LICENSE file as license and not doc drools: - Declare the LICENSE file as license and not doc jakarta-commons-validator: - Declare the LICENSE file as license and not doc jose4j: - Declare the LICENSE file as license and not doc kie-api: - Declare the LICENSE file as license and not doc mvel2: - Declare the LICENSE file as license and not doc optaplanner: - Declare the LICENSE file as license and not doc py27-compat-salt: - Remove redundant overrides causing confusing DEBUG logging (bsc#1189501) python-susemanager-retail: - Update to version 1.0.1653987003.92d4870 * Fix messages and logging in retail_create_delta (bsc#1199727) smdba: - Declare the LICENSE file as license and not doc - Make EL egginfo removal more generic spacecmd: - Version 4.2.18-1 * on full system update call schedulePackageUpdate API (bsc#1197507) spacewalk-admin: - Version 4.2.11-1 * clarify schema upgrade check message (bsc#1198999) spacewalk-backend: - Version 4.2.23-1 * Fix traceback on calling spacewalk-repo-sync --show-packages (bsc#1193238) * Fix virt_notify SQL syntax error (bsc#1199528) * store create-bootstrap logs in spacewalk-debug spacewalk-branding: - Version 4.2.14-1 * Stylesheets and relevant assets are now provided by spacewalk-web spacewalk-certs-tools: - Version 4.2.17-1 * use RES bootstrap repo as a fallback for Red Hat downstream OS (bsc#1200087) spacewalk-client-tools: - Version 4.2.19-1 * Update translation strings spacewalk-java: - version 4.2.40-1 * Fix conflict when system is assigned to multiple instances of the same formula (bsc#1194394) - Version 4.2.39-1 * Keep the websocket connections alive with ping/pong frames (bsc#1199874) * Fix missing remote command history events for big output (bsc#1199656) * Improve CLM channel cloning performance (bsc#1199523) * fix api log message references the wrong user (bsc#1179962) * Show patch as installed in CVE Audit even if successor patch affects additional packages (bsc#1199646) * fix download of packages with caret sign in the version due to missing url decode * Prefer the Salt Bundle with Cobbler snippets configuration (minion_script and redhat_register_using_salt) (bsc#1198646) * During re-activation, recalculate grains if contact method has been changed (bsc#1199677) * Hide authentication data in PAYG UI (bsc#1199679) * autoinstallation: missing whitespace after install URL (bsc#1199888) * Improved handling of error messages during bootstrapping * skip forwarding data to scc if no credentials are available * Change system details lock tab name to lock/unlock (bsc#1193032) * Added a notification to inform the administrators about the product end-of-life * Set profile tag has no-mandatory in XCCDF result (bsc#1194262) * provisioning thought proxy should use proxy for self_update (bsc#1199036) * Allow removing duplicated packages names in the same Salt action (bsc#1198686) * fix NoSuchElementException when pkg install date is missing * Improve API documentation * Fix outdated documentation and release notes links * Fix error message in Kubernetes VHM creation dialog * Add createAppStreamFilters() XMLRPC function * Correct concurrency error on payg taskomatic task for updating certificates (#17783) * Fix ACL rules for config diff download for SLS files (bsc#1198914) * fix package selection for ubuntu errata install (bsc#1199049) * fix invalid link to action schedule * add schedulePackageUpdate() XMLRPC function (bsc#1197507) * update server needed cache after adding Ubuntu Errata (bsc#1196977) * check if file exists before sending it to xsendfile (bsc#1198191) * Display usertime instead of server time for clm issue date filter (bsc#1198429) * Redesign the auto errata task to schedule combined actions (bsc#1197429) * Fix send login(s) and send password actions to avoid user enumeration (bsc#1199629) (CVE-2022-31248) spacewalk-search: - Version 4.2.7-1 * Update development configuration file spacewalk-setup: - Version 4.2.11-1 * spacewalk-setup-cobbler assumes /etc/apache2/conf.d now as a default instead of /etc/httpd/conf.d (bsc#1198356) spacewalk-utils: - Version 4.2.17-1 * spacewalk-hostname-rename now correctly replaces the hostname for the mgr-sync configuration file (bsc#1198356) * spacewalk-hostname-rename now utilizes the '--apache2-conf-dir' flag for spacewalk-setup-cobbler (bsc#1198356) spacewalk-web: - Version 4.2.28-1 * Stylesheets and relevant assets are now provided by spacewalk-web * Remove nodejs-packaging as a build requirement * Hide authentication data in PAYG UI (bsc#1199679) * Improved handling of error messages during bootstrapping * Added support for end of life notifications * Improved test integration for dropdowns * Upgrade moment to 2.29.2 * Fix outdated documentation and release notes links * Fix mimetype in kubeconfig validation request (bsc#1199019) subscription-matcher: - Declare the LICENSE file as license and not doc susemanager: - version 4.2.35-1 * Add missing python3-gnupg to Debian10 bootstrap repo (bsc#1201842) - Version 4.2.34-1 * mgr-sync: Raise a proper exception when duplicated lines exist in a config file (bsc#1182742) * add SLED 12 SP3 bootstrap repo definition (bsc#1199438) - Version 4.2.33-1 * Fix issue with bootstrap repo definitions for RHEL/RES8 variants (bsc#1200863) susemanager-doc-indexes: - Fixed the 'fast' switch ('-f') of the database migration script in the Installation and Upgrade Guides - Updated the Virtualization chapter in the Client Configuration Guide - Added information about registering RHEL clients on Azure in the Import Entitlements and Certificates section of the Client Configuration Guide (bsc#1198944) - In the Client Configuration Guide, package locking is now supported for Ubuntu and Debian - Fixed VisibleIf documentation in the Formula section of the Salt Guide - Added note about importing CA certifcates in the Installation and Upgrade Guide (bsc#1198358) - Documented how to define monitored targets using the file-based service discovery provided in the Prometheus formula of the Salt Guide - Add note about OpenSCAP security profile support in OpenSCAP section of the Administration Guide - Fixed spacewalk-remove-channel command in Delete Channels section of the Administration Guide (bsc#1199596) - Large deployments guide now includes a mention of the proxy (bsc#1199577) - Enhanced the Product Migration chapter of the Client Configuration Guide with a SUSE Linux Enterprise example susemanager-docs_en: - Fixed the 'fast' switch ('-f') of the database migration script in the Installation and Upgrade Guides - Updated the Virtualization chapter in the Client Configuration Guide - Added information about registering RHEL clients on Azure in the Import Entitlements and Certificates section of the Client Configuration Guide (bsc#1198944) - In the Client Configuration Guide, package locking is now supported for Ubuntu and Debian - Fixed VisibleIf documentation in the Formula section of the Salt Guide - Added note about importing CA certifcates in the Installation and Upgrade Guide (bsc#1198358) - Documented how to define monitored targets using the file-based service discovery provided in the Prometheus formula of the Salt Guide - Add note about OpenSCAP security profile support in OpenSCAP section of the Administration Guide - Fixed spacewalk-remove-channel command in Delete Channels section of the Administration Guide (bsc#1199596) - Large deployments guide now includes a mention of the proxy (bsc#1199577) - Enhanced the Product Migration chapter of the Client Configuration Guide with a SUSE Linux Enterprise example susemanager-schema: - Version 4.2.23-1 * Add schema directory for susemanager-schema-4.2.22 susemanager-sls: - version 4.2.26-1 * Fix issue bootstrap issue with Debian 9 because missing python3-contextvars (bsc#1201782) - Version 4.2.25-1 * use RES bootstrap repo as a fallback for Red Hat downstream OS (bsc#1200087) * Add support to packages.pkgremove to deal with duplicated pkg names (bsc#1198686) * do not install products and gpg keys when performing distupgrade dry-run (bsc#1199466) * Fix deprecated warning when getting pillar data (bsc#1192850) * remove unknown repository flags on EL * add packages.pkgupdate state (bsc#1197507) - Version 4.2.24-1 * Manage the correct minion config file when venv-salt-minion is installed (bsc#1200703) * Fix bootstrapping for Ubuntu 18.04 with classic Salt package (bsc#1200707) susemanager-sync-data: - Version 4.2.13-1 * change release status of Debian 11 to released virtual-host-gatherer: - Declare the LICENSE file as license and not doc woodstox: - Declare the LICENSE file as license and not doc xmlpull-api: - Declare the LICENSE file as license and not doc How to apply this update: 1. Log in as root user to the SUSE Manager server. 2. Stop the Spacewalk service: `spacewalk-service stop` 3. Apply the patch using either zypper patch or YaST Online Update. 4. Start the Spacewalk service: `spacewalk-service start`
References: https://www.suse.com/support/update/announcement/2022/suse-su-20222568-1/, https://bugzilla.suse.com/1179962, https://bugzilla.suse.com/1182742, https://bugzilla.suse.com/1189501, https://bugzilla.suse.com/1192850, https://bugzilla.suse.com/1193032, https://bugzilla.suse.com/1193238, https://bugzilla.suse.com/1194262, https://bugzilla.suse.com/1194394, https://bugzilla.suse.com/1196977, https://bugzilla.suse.com/1197429, https://bugzilla.suse.com/1197507, https://bugzilla.suse.com/1198191, https://bugzilla.suse.com/1198356, https://bugzilla.suse.com/1198358, https://bugzilla.suse.com/1198429, https://bugzilla.suse.com/1198646, https://bugzilla.suse.com/1198686, https://bugzilla.suse.com/1198914, https://bugzilla.suse.com/1198944, https://bugzilla.suse.com/1198999, https://bugzilla.suse.com/1199019, https://bugzilla.suse.com/1199036, https://bugzilla.suse.com/1199049, https://bugzilla.suse.com/1199438, https://bugzilla.suse.com/1199466, https://bugzilla.suse.com/1199523, https://bugzilla.suse.com/1199528, https://bugzilla.suse.com/1199577, https://bugzilla.suse.com/1199596, https://bugzilla.suse.com/1199629, https://bugzilla.suse.com/1199646, https://bugzilla.suse.com/1199656, https://bugzilla.suse.com/1199677, https://bugzilla.suse.com/1199679, https://bugzilla.suse.com/1199727, https://bugzilla.suse.com/1199874, https://bugzilla.suse.com/1199888, https://bugzilla.suse.com/1200087, https://bugzilla.suse.com/1200703, https://bugzilla.suse.com/1200707, https://bugzilla.suse.com/1200863, https://bugzilla.suse.com/1201782, https://bugzilla.suse.com/1201842, https://www.suse.com/security/cve/CVE-2022-31248
Affected packages
Package
Name: apache-commons-csv
Purl: pkg:rpm/suse/apache-commons-csv&distro=SUSE%20Manager%20Server%20Module%204.2
Affected ranges
Type: ECOSYSTEM
Events:
