SUSE-SU-2023:4387-1
Dashboard / Vulnerabilities / SUSE-SU-2023:4387-1
SUSE-SU-2023:4387-1
Summary: Security update for salt
Details: This update for salt fixes the following issues: Security issues fixed: - CVE-2023-34049: arbitrary code execution via symlink attack (bsc#1215157) Bugs fixed: - Fix optimization_order opt to prevent testsuite fails - Improve salt.utils.json.find_json to avoid fails (bsc#1213293) - Use salt-call from salt bundle with transactional_update - Only call native_str on curl_debug message in tornado when needed - Implement the calling for batch async from the salt CLI - Fix calculation of SLS context vars when trailing dots on targetted sls/state (bsc#1213518) - Rename salt-tests to python3-salt-testsuite - Allow all primitive grain types for autosign_grains (bsc#1214477)
References: https://www.suse.com/support/update/announcement/2023/suse-su-20234387-1/, https://bugzilla.suse.com/1213293, https://bugzilla.suse.com/1213518, https://bugzilla.suse.com/1214477, https://bugzilla.suse.com/1215157, https://www.suse.com/security/cve/CVE-2023-34049
Affected packages
Package
Name: salt
Purl: pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Micro%205.3
Affected ranges
Type: ECOSYSTEM
Events:
