SUSE: 2024:4021-1 important: SUSE Manager Salt Bundle Security Advisory Updates
Summary
## This update fixes the following issues: venv-salt-minion: * Security fixes on Python 3.11 interpreter: * CVE-2024-7592: Fixed quadratic complexity in parsing -quoted cookie values with backslashes (bsc#1229873, bsc#1230059) * CVE-2024-8088: Prevent malformed payload to cause infinite loops in zipfile.Path (bsc#1229704, bsc#1230058) * CVE-2024-6923: Prevent email header injection due to unquoted newlines (bsc#1228780) * CVE-2024-4032: Rearranging definition of private global IP addresses (bsc#1226448) * CVE-2024-0397: ssl.SSLContext.cert_store_stats() and ssl.SSLContext.get_ca_certs() now correctly lock access to the certificate store, when the ssl.SSLContext is shared across multiple threads (bsc#1226447) * Security fixes on Python dependencies: * CVE-2024-5569: zipp: Fixed a Denial of Service (DoS) vulnerability in the jaraco/zipp library (bsc#1227547, bsc#1229996) * CVE-2024-6345: setuptools: Sanitize any VCS URL used f...
Read the Full AdvisoryReferences
* bsc#1219041
* bsc#1220357
* bsc#1222842
* bsc#1226141
* bsc#1226447
* bsc#1226448
* bsc#1226469
* bsc#1227547
* bsc#1228105
* bsc#1228780
* bsc#1229109
* bsc#1229539
* bsc#1229654
* bsc#1229704
* bsc#1229873
* bsc#1229994
* bsc#1229995
* bsc#1229996
* bsc#1230058
* bsc#1230059
* bsc#1230322
* bsc#1231045
* bsc#1231697
* jsc#MSQA-863
Cross-
* CVE-2024-0397
* CVE-2024-3651
* CVE-2024-37891
* CVE-2024-4032
* CVE-2024-5569
* CVE-2024-6345
* CVE-2024-6923
* CVE-2024-7592
* CVE-2024-8088
CVSS scores:
* CVE-2024-0397 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
* CVE-2024-3651 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2024-3651 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2024-37891 ( SUSE ): 4.4 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
* CVE-2024-4032 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2024-5569 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
...
Read the Full Advisory