openSUSE-SU-2021:1951-1
Dashboard / Vulnerabilities / openSUSE-SU-2021:1951-1
openSUSE-SU-2021:1951-1
Summary: Security update for salt
Details: This update for salt fixes the following issues: - Check if dpkgnotify is executable (bsc#1186674) - Update to Salt release version 3002.2 (jsc#ECO-3212, jsc#SLE-18033, jsc#SLE-18028) - Drop support for Python2. Obsoletes `python2-salt` package (jsc#SLE-18028) - Fix issue parsing errors in ansiblegate state module - Prevent command injection in the snapper module (bsc#1185281, CVE-2021-31607) - transactional_update: detect recursion in the executor - Add subpackage `salt-transactional-update` (jsc#SLE-18033) - Remove duplicate directories
References: https://lists.opensuse.org/archives/list/[email protected]/thread/BSSCTPCNB3RDCWJ6DOALIIRKDXUAVGPB/, https://bugzilla.suse.com/1185281, https://bugzilla.suse.com/1186674, https://www.suse.com/security/cve/CVE-2021-31607
Affected packages
Package
Name: salt
Purl: pkg:rpm/opensuse/salt&distro=openSUSE%20Leap%2015.3
Affected ranges
Type: ECOSYSTEM
Events:
