{"schema_version":"1.7.5","id":"SUSE-EL-9-CLIENT-TOOLS-2023-3884","published":"2023-09-28T11:51:44Z","modified":"2026-07-24T18:24:18.247211757Z","related":["CVE-2023-20897","CVE-2023-20898"],"upstream":["CVE-2023-20897","CVE-2023-20898"],"summary":"Security update for SUSE Manager Salt Bundle","details":"This update fixes the following issues:\n\nvenv-salt-minion:\n\n- Security issues fixed:  \n  * CVE-2023-20897: Do not fail on bad message pack message (bsc#1213441)  \n  * CVE-2023-20898: Fixed Git Providers can read from the wrong environment because they get the same cache directory\n    base name. (bsc#1214797, bsc#1193948)\n- Bugs fixed:\n  * Revert usage of long running REQ channel to prevent possible missing responses on requests and duplicated\n    responses (bsc#1213960, bsc#1213630, bsc#1213257)\n  * Create minion_id with reproducible mtime\n  * Do not recompile SELinux policy module on building. Use precompiled module instead to avoid incompatibility errors.\n  * Fix broken tests to make them running in the testsuite\n  * Fix detection of Salt codename by 'salt_version' execution module\n  * Fix inconsistency in reported version by egg-info metadata (bsc#1215489)\n  * Fix regression: multiple values for keyword argument 'saltenv' (bsc#1212844)\n  * Fix the regression of user.present state when group is unset (bsc#1212855)\n  * Fix utf8 handling in 'pass' renderer and make it more robust\n  * Fix zypper repositories always being reconfigured\n  * Make sure configured user is properly set by Salt (bsc#1210994)\n  * Prevent possible exceptions on salt.utils.user.get_group_dict (bsc#1212794)\n  * Ship SELinux policy module version 19 to make it compatible with broader list of Linux distributions\n","affected":[{"package":{"name":"venv-salt-minion","ecosystem":"SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS","purl":"pkg:rpm/suse/venv-salt-minion&distro=SUSE%20Manager%20Client%20Tools%20for%20RHEL,%20Liberty%20and%20Clones%209-CLIENT-TOOLS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3006.0-1.24.1"}]}],"ecosystem_specific":{"binaries":[{"venv-salt-minion":"3006.0-1.24.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-EL-9-CLIENT-TOOLS-2023-3884.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement//suse-el-9-client-tools-2023-3884/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1193948"},{"type":"REPORT","url":"https://bugzilla.suse.com/1210994"},{"type":"REPORT","url":"https://bugzilla.suse.com/1212794"},{"type":"REPORT","url":"https://bugzilla.suse.com/1212844"},{"type":"REPORT","url":"https://bugzilla.suse.com/1212855"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213257"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213441"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213630"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213960"},{"type":"REPORT","url":"https://bugzilla.suse.com/1214796"},{"type":"REPORT","url":"https://bugzilla.suse.com/1214797"},{"type":"REPORT","url":"https://bugzilla.suse.com/1215489"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-20897"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-20898"}]}