Security update for SUSE Manager Server 4.2

Announcement ID: SUSE-SU-2023:2594-1
Rating: important
References:
Cross-References:
CVSS scores:
  • CVE-2022-46146 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • CVE-2022-46146 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • CVE-2023-22644 ( NVD ): 3.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Affected Products:
  • openSUSE Leap 15.3
  • SUSE Manager Proxy 4.2
  • SUSE Manager Retail Branch Server 4.2
  • SUSE Manager Server 4.2

An update that solves two vulnerabilities, contains one feature and has 35 security fixes can now be installed.

Recommended update for SUSE Manager Proxy and Retail Branch Server 4.2

Description:

This update fixes the following issues:

release-notes-susemanager-proxy:

  • Update to 4.2.13
  • Bugs mentioned: bsc#1179747, bsc#1207814, bsc#1209231, bsc#1210437, bsc#1210458

Security update for SUSE Manager Server 4.2

Description:

This update fixes the following issues:

release-notes-susemanager:

  • Update to 4.2.13
  • Salt has been upgraded to 3006.0
  • SUSE Linux Enterprise Server 15 SP5 Family support has been added
  • openSUSE Leap 15.5 support has been added
  • Automatic migration from Salt 3000 to Salt bundle
  • Grafana upgraded to 9.5.1
  • Node exporter upgraded to 1.5.0
  • Prometheus upgraded to 2.37.6
  • Postgres exporter upgraded to 0.10.1
  • CVEs fixed: CVE-2023-22644, CVE-2022-46146
  • Bugs mentioned: bsc#1179747, bsc#1186011, bsc#1203599, bsc#1205600, bsc#1206423 bsc#1207550, bsc#1207814, bsc#1207941, bsc#1208984, bsc#1209220 bsc#1209231, bsc#1209277, bsc#1209386, bsc#1209434, bsc#1209508 bsc#1209877, bsc#1209915, bsc#1209926, bsc#1210011, bsc#1210086 bsc#1210101, bsc#1210107, bsc#1210154, bsc#1210162, bsc#1210232 bsc#1210311, bsc#1210406, bsc#1210437, bsc#1210458, bsc#1210659 bsc#1210835, bsc#1210957, bsc#1211330, bsc#1208046, bsc#1212517 bsc#1212096

Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

  • SUSE Manager Retail Branch Server 4.2
    zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch-Server-4.2-2023-2594=1
  • SUSE Manager Server 4.2
    zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.2-2023-2594=1
  • openSUSE Leap 15.3
    zypper in -t patch SUSE-2023-2594=1
  • SUSE Manager Proxy 4.2
    zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.2-2023-2594=1

Package List:

  • SUSE Manager Retail Branch Server 4.2 (noarch)
    • release-notes-susemanager-proxy-4.2.13-150300.3.64.2
  • SUSE Manager Server 4.2 (noarch)
    • release-notes-susemanager-4.2.13-150300.3.81.1
  • openSUSE Leap 15.3 (noarch)
    • release-notes-susemanager-proxy-4.2.13-150300.3.64.2
    • release-notes-susemanager-4.2.13-150300.3.81.1
  • SUSE Manager Proxy 4.2 (noarch)
    • release-notes-susemanager-proxy-4.2.13-150300.3.64.2

References: