SUSE: 2020:1057-1 moderate: puppet
Summary
This update for puppet fixes the following issues: - CVE-2020-7942: Added a warning for a vulnerable configuration option, which could allow for information disclosure in certain setups. Disabling it my break some setups. (bsc#1167645) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Advanced Systems Management 12: zypper in -t patch SUSE-SLE-Module-Adv-Systems-Management-12-2020-1057=1 Package List: - SUSE Linux Enterprise Module for Advanced Systems Management 12 (ppc64le s390x x86_64): puppet-3.8.5-15.12.1 puppet-server-3.8.5-15.12.1
References
#1167645
Cross- CVE-2020-7942
Affected Products:
SUSE Linux Enterprise Module for Advanced Systems Management 12
https://www.suse.com/security/cve/CVE-2020-7942.html
https://bugzilla.suse.com/1167645