{"schema_version":"1.7.3","id":"openSUSE-SU-2020:0357-1","published":"2020-03-18T15:18:47Z","modified":"2026-02-04T03:45:15.939882Z","related":["CVE-2019-17361","CVE-2019-18897"],"upstream":["CVE-2019-17361","CVE-2019-18897"],"summary":"Security update for salt","details":"This update for salt fixes the following issues:\n\n- Avoid possible user escalation upgrading salt-master (bsc#1157465) (CVE-2019-18897)\n- Fix unit tests failures in test_batch_async tests\n- Batch Async: Handle exceptions, properly unregister and close instances after\n  running async batching to avoid CPU starvation of the MWorkers (bsc#1162327)\n- RHEL/CentOS 8 uses platform-python instead of python3\n- New configuration option for selection of grains in the minion start event.\n- Fix 'os_family' grain for Astra Linux Common Edition\n- Fix for salt-api NET API where unauthenticated attacker could run\n  arbitrary code (CVE-2019-17361) (bsc#1162504)\n- Adds disabled parameter to mod_repo in aptpkg module\n  Move token with atomic operation\n  Bad API token files get deleted (bsc#1160931)\n- Support for Btrfs and XFS in parted and mkfs added\n- Adds list_downloaded for apt Module to enable pre-downloading support\n  Adds virt.(pool|network)_get_xml functions\n- Various libvirt updates:\n  * Add virt.pool_capabilities function\n  * virt.pool_running improvements\n  * Add virt.pool_deleted state\n  * virt.network_define allow adding IP configuration\n- virt: adding kernel boot parameters to libvirt xml\n- Fix to scheduler when data['run'] does not exist (bsc#1159118)\n- Fix virt states to not fail on VMs already stopped\n- Fix applying of attributes for returner rawfile_json (bsc#1158940)\n- xfs: do not fail if type is not present (bsc#1153611)\n- Fix errors when running virt.get_hypervisor function\n- Align virt.full_info fixes with upstream Salt\n- Fix for log checking in x509 test\n- Read repo info without using interpolation (bsc#1135656)\n- Limiting M2Crypto to >= SLE15\n- Replacing pycrypto with M2Crypto (bsc#1165425)\n\nThis update was imported from the SUSE:SLE-15-SP1:Update update project.","affected":[{"package":{"name":"salt","ecosystem":"openSUSE:Leap 15.1","purl":"pkg:rpm/opensuse/salt&distro=openSUSE%20Leap%2015.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2019.2.0-lp151.5.12.1"}]}],"ecosystem_specific":{"binaries":[{"python2-salt":"2019.2.0-lp151.5.12.1","python3-salt":"2019.2.0-lp151.5.12.1","salt":"2019.2.0-lp151.5.12.1","salt-api":"2019.2.0-lp151.5.12.1","salt-bash-completion":"2019.2.0-lp151.5.12.1","salt-cloud":"2019.2.0-lp151.5.12.1","salt-doc":"2019.2.0-lp151.5.12.1","salt-fish-completion":"2019.2.0-lp151.5.12.1","salt-master":"2019.2.0-lp151.5.12.1","salt-minion":"2019.2.0-lp151.5.12.1","salt-proxy":"2019.2.0-lp151.5.12.1","salt-ssh":"2019.2.0-lp151.5.12.1","salt-standalone-formulas-configuration":"2019.2.0-lp151.5.12.1","salt-syndic":"2019.2.0-lp151.5.12.1","salt-zsh-completion":"2019.2.0-lp151.5.12.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:0357-1.json"}}],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/PR2PQ3GKS2PLFHVBID4QWOIOSORFRWDH/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1135656"},{"type":"REPORT","url":"https://bugzilla.suse.com/1153611"},{"type":"REPORT","url":"https://bugzilla.suse.com/1157465"},{"type":"REPORT","url":"https://bugzilla.suse.com/1158940"},{"type":"REPORT","url":"https://bugzilla.suse.com/1159118"},{"type":"REPORT","url":"https://bugzilla.suse.com/1160931"},{"type":"REPORT","url":"https://bugzilla.suse.com/1162327"},{"type":"REPORT","url":"https://bugzilla.suse.com/1162504"},{"type":"REPORT","url":"https://bugzilla.suse.com/1165425"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-17361"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-18897"}]}