{"schema_version":"1.7.3","id":"SUSE-SU-2023:3877-1","published":"2023-09-28T11:47:21Z","modified":"2026-02-04T03:27:17.094733Z","related":["CVE-2023-20897","CVE-2023-20898"],"upstream":["CVE-2023-20897","CVE-2023-20898"],"summary":"Security update for SUSE Manager Salt Bundle","details":"This update fixes the following issues:\n\nvenv-salt-minion:\n\n- Security issues fixed:  \n  * CVE-2023-20897: Do not fail on bad message pack message (bsc#1213441)  \n  * CVE-2023-20898: Fixed Git Providers can read from the wrong environment because they get the same cache directory\n    base name. (bsc#1214797, bsc#1193948)\n- Bugs fixed:\n  * Revert usage of long running REQ channel to prevent possible missing responses on requests and duplicated\n    responses (bsc#1213960, bsc#1213630, bsc#1213257)\n  * Create minion_id with reproducible mtime\n  * Do not recompile SELinux policy module on building. Use precompiled module instead to avoid incompatibility errors.\n  * Fix broken tests to make them running in the testsuite\n  * Fix detection of Salt codename by 'salt_version' execution module\n  * Fix inconsistency in reported version by egg-info metadata (bsc#1215489)\n  * Fix regression: multiple values for keyword argument 'saltenv' (bsc#1212844)\n  * Fix the regression of user.present state when group is unset (bsc#1212855)\n  * Fix utf8 handling in 'pass' renderer and make it more robust\n  * Fix zypper repositories always being reconfigured\n  * Make sure configured user is properly set by Salt (bsc#1210994)\n  * Prevent possible exceptions on salt.utils.user.get_group_dict (bsc#1212794)\n  * Ship SELinux policy module version 19 to make it compatible with broader list of Linux distributions\n","affected":[{"package":{"name":"venv-salt-minion","ecosystem":"SUSE:Manager Client Tools 15","purl":"pkg:rpm/suse/venv-salt-minion&distro=SUSE%20Manager%20Client%20Tools%2015"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3006.0-150000.3.42.1"}]}],"ecosystem_specific":{"binaries":[{"venv-salt-minion":"3006.0-150000.3.42.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3877-1.json"}},{"package":{"name":"venv-salt-minion","ecosystem":"SUSE:Manager Client Tools for SLE Micro 5","purl":"pkg:rpm/suse/venv-salt-minion&distro=SUSE%20Manager%20Client%20Tools%20for%20SLE%20Micro%205"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3006.0-150000.3.42.1"}]}],"ecosystem_specific":{"binaries":[{"venv-salt-minion":"3006.0-150000.3.42.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3877-1.json"}},{"package":{"name":"venv-salt-minion","ecosystem":"SUSE:Manager Proxy Module 4.3","purl":"pkg:rpm/suse/venv-salt-minion&distro=SUSE%20Manager%20Proxy%20Module%204.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3006.0-150000.3.42.1"}]}],"ecosystem_specific":{"binaries":[{"venv-salt-minion":"3006.0-150000.3.42.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3877-1.json"}},{"package":{"name":"venv-salt-minion","ecosystem":"SUSE:Manager Server Module 4.3","purl":"pkg:rpm/suse/venv-salt-minion&distro=SUSE%20Manager%20Server%20Module%204.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3006.0-150000.3.42.1"}]}],"ecosystem_specific":{"binaries":[{"venv-salt-minion":"3006.0-150000.3.42.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3877-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20233877-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1193948"},{"type":"REPORT","url":"https://bugzilla.suse.com/1210994"},{"type":"REPORT","url":"https://bugzilla.suse.com/1212794"},{"type":"REPORT","url":"https://bugzilla.suse.com/1212844"},{"type":"REPORT","url":"https://bugzilla.suse.com/1212855"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213257"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213441"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213630"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213960"},{"type":"REPORT","url":"https://bugzilla.suse.com/1214796"},{"type":"REPORT","url":"https://bugzilla.suse.com/1214797"},{"type":"REPORT","url":"https://bugzilla.suse.com/1215489"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-20897"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-20898"}]}