SUSE-SU-2026:4582-1
Vulnerability from csaf_suse - Published: 2026-10-08 08:20 - Updated: 2026-10-08 18:00Summary
Security update 5.2.1 for Multi-Linux Manager Client Tools
Severity
Important
Notes
Title of the patch: Security update 5.2.1 for Multi-Linux Manager Client Tools
Description of the patch: This update fixes the following issues:
scap-security-guide was updated to version 0.1.79:
- Version 0.1.79 (jsc#ECO-3319)
* Added SLE16 profiles to the build
* Create SLE16 HIPAA profile
* Create SLE16 PCI DSS 4 profile
* Use Sequoia in RHEL 10 instead of GPG
* New Profile for RHEL10: BSI
* Move RHEL Control files to product files
* Update RHEL 9 CCN profile
* Various updates for SLE 12/15
spacecmd was updated to version 5.2.10:
- Version 5.2.10:
* Pre-filter errata in system_applyerrata to avoid using API calls for all existing errata (bsc#1267261)
- Version 5.2.9:
* Updated translation strings
uyuni-tools was updated to version 5.2.17:
Security issues fixed:
- CVE-2026-39821: Drop the direct dependency on golang.org/x/net (bsc#1266481) - fixed in 5.2.17-0
Bug fixes and changes:
- Version 5.2.17-0:
* Bump the default image tag to 5.2.1
* Reload systemd daemon before restarting services (bsc#1270033)
* Check all supported locations for CA file in rotation check script
* Detect and fix legacy service file (bsc#1268755)
* Use healthcheck cmd from the image (bsc#1273144)
- Version 5.2.16-0:
* Reverted usage of sdnotify as it causes issues with Podman (bsc#1270399, bsc#1270398)
- Version 5.2.15-0:
* Added requirement for at least Podman v4.7.2
* Send READY notification to systemd only once healthy (bsc#1263823)
- Version 5.2.14-0:
* Include the server environment file in the backup (bsc#1268649)
* Added mgradm commands for SSL CA and certificate rotation
- Version 5.2.13-0:
* Check and warn if CA certificate isn't marked as critical
* Disable SSL on database during split (bsc#1267980)
* Do not call uyuni-postgres-config.sh in mgradm (bsc#1267980)
* Check backup status only after database is started (bsc#1262492)
venv-salt-minion:
- Security issues:
* CVE-2026-13346: Fixed an issue where malicious package indexes could install unauthorized files (bsc#1273094)
* CVE-2026-0864: Fixed custom configuration injection risks caused by improper line-ending validation (bsc#1269066)
* CVE-2026-1502: Fixed web request header manipulation to bypass proxy security protections (bsc#1261969)
* CVE-2026-3276: Fixed potential system slow down or freeze when processing crafted Unicode text (bsc#1267581)
* CVE-2026-4360: Fixed directory escape risks during archive extraction (bsc#1269959)
* CVE-2026-4786: Fixed command injection risks when processing malicious browser links (bsc#1262319)
* CVE-2026-6019: Fixed a flaw where cookies could be manipulated to run malicious script (bsc#1262654)
* CVE-2026-6100: Fixed crashes or unauthorized code execution during file decompression (bsc#1262098)
* CVE-2026-7210: Fixed system freezes triggered by parsing malicious XML files (bsc#1264962)
* CVE-2026-7774: Fixed path traversal risks where malicious archives write files outside targets (bsc#1267821)
* CVE-2026-8328: Fixed connections being redirected to unsafe systems by compromised FTP servers (bsc#1265268)
* CVE-2026-11940: Fixed a bug where extracting malicious archives could overwrite system files (bsc#1268977)
* CVE-2026-11972: Fixed infinite loop and system freeze risks during archive decompression (bsc#1269788)
* CVE-2026-15308: Fixed crashes when parsing web pages with repetitive, incomplete structures (bsc#1271192)
* CVE-2026-8643: Fixed malicious package installs overwriting arbitrary local files (bsc#1266669)
* CVE-2026-6357: Fixed package self-updates loading unauthorized modules during install (bsc#1263442)
* CVE-2026-3219: Fixed validation failures where combined ZIP archives were not rejected (bsc#1262429)
* CVE-2026-1703: Fixed package installations writing files outside target directories (bsc#1257599)
* CVE-2024-22195: Fixed HTML template manipulation allowing unauthorized script execution (bsc#1218722)
* CVE-2026-45409: Fixed domain name encoding bypass allowing imitation websites (bsc#1265413)
* CVE-2026-44431: Fixed data leaks where sensitive headers were sent to external origins (bsc#1265267)
* CVE-2026-49825: Fixed missing script cleanup from namespaces in web content (bsc#1270285)
* CVE-2026-41066: Fixed leakage of private system data via malicious XML file parsing (bsc#1263254)
* CVE-2026-3446: Fixed validation bypasses where hidden excess Base64 data was ignored (bsc#1261970)
* CVE-2026-3479: Fixed path traversal risks when loading packages from insecure locations (bsc#1259989)
* CVE-2026-27459: Fixed buffer overflow vulnerabilities caused by large cookie headers (bsc#1271428)
* CVE-2026-49853: Fixed credentials leakage during redirects to cross-origin servers (bsc#1268395)
* CVE-2026-49854: Fixed crashes or unauthorized memory access in compiled components (bsc#1268396)
* CVE-2026-49855: Fixed crashes caused by excessively compressed files exhausting memory (bsc#1268397)
* CVE-2026-40475: Fixed silent data truncation where hidden null characters bypass checks (bsc#1262803)
* CVE-2025-13836: Fixed memory exhaustion risk by limiting HTTP response reading size (bsc#1254400)
- Bug fixes and changes:
* Updated bundled python module pip to 25.0.1
* Updated bundled python module jinja2 to 3.1.6
* Updated bundled python module lxml to 6.1.1
* Prevent broken Salt Bundle on Ubuntu due regression in 'tar' package from Ubuntu repositories (bsc#1271613)
* Remove unused paramiko python module from the bundle.
* Switch apache2ctl to apachectl for SUSE OSes (bsc#1252286)
* Support attrlist in ldap.managed (bsc#1257151)
* Use AsyncHTTPClient in salt.utils.http (bsc#1268325)
* Decode binary pillars for salt-ssh to avoid exceptions (bsc#1263822)
Patchnames: SUSE-2026-4582,SUSE-MultiLinuxManagerTools-EL-9-2026-4582
Terms of use: CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
5.4 (Medium)
Affected products
Recommended
99 products
| Product | Identifier | Version | Remediation |
|---|---|---|---|
| Unresolved product id: SUSE Multi Linux Manager Tools EL-9:mgrctl-0:5.2.17-90002.3.15.1.aarch64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Multi Linux Manager Tools EL-9:mgrctl-0:5.2.17-90002.3.15.1.ppc64le | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Multi Linux Manager Tools EL-9:mgrctl-0:5.2.17-90002.3.15.1.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Multi Linux Manager Tools EL-9:mgrctl-0:5.2.17-90002.3.15.1.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Multi Linux Manager Tools EL-9:mgrctl-bash-completion-0:5.2.17-90002.3.15.1.noarch | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Multi Linux Manager Tools EL-9:mgrctl-zsh-completion-0:5.2.17-90002.3.15.1.noarch | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Multi Linux Manager Tools EL-9:scap-security-guide-redhat-0:0.1.80-90002.3.12.1.noarch | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Multi Linux Manager Tools EL-9:spacecmd-0:5.2.10-90002.3.15.1.noarch | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Multi Linux Manager Tools EL-9:venv-salt-minion-0:3006.0-90002.5.22.1.aarch64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Multi Linux Manager Tools EL-9:venv-salt-minion-0:3006.0-90002.5.22.1.ppc64le | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Multi Linux Manager Tools EL-9:venv-salt-minion-0:3006.0-90002.5.22.1.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Multi Linux Manager Tools EL-9:venv-salt-minion-0:3006.0-90002.5.22.1.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:mgrctl-0:5.2.17-90002.3.15.1.aarch64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:mgrctl-0:5.2.17-90002.3.15.1.ppc64le | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:mgrctl-0:5.2.17-90002.3.15.1.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:mgrctl-0:5.2.17-90002.3.15.1.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:mgrctl-bash-completion-0:5.2.17-90002.3.15.1.noarch | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:mgrctl-zsh-completion-0:5.2.17-90002.3.15.1.noarch | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-0:3.11.15-90002.4.15.1.aarch64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-0:3.11.15-90002.4.15.1.ppc64le | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-0:3.11.15-90002.4.15.1.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-0:3.11.15-90002.4.15.1.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-base-0:3.11.15-90002.4.15.1.aarch64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-base-0:3.11.15-90002.4.15.1.ppc64le | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-base-0:3.11.15-90002.4.15.1.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-base-0:3.11.15-90002.4.15.1.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-cffi-0:1.17.1-90002.3.6.2.aarch64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-cffi-0:1.17.1-90002.3.6.2.ppc64le | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-cffi-0:1.17.1-90002.3.6.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-cffi-0:1.17.1-90002.3.6.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-cryptography-0:3.3.2-90002.3.6.2.aarch64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-cryptography-0:3.3.2-90002.3.6.2.ppc64le | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-cryptography-0:3.3.2-90002.3.6.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-cryptography-0:3.3.2-90002.3.6.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-cssselect-0:1.3.0-90002.3.6.2.noarch | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-curses-0:3.11.15-90002.4.15.1.aarch64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-curses-0:3.11.15-90002.4.15.1.ppc64le | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-curses-0:3.11.15-90002.4.15.1.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-curses-0:3.11.15-90002.4.15.1.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-dbm-0:3.11.15-90002.4.15.1.aarch64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-dbm-0:3.11.15-90002.4.15.1.ppc64le | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-dbm-0:3.11.15-90002.4.15.1.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-dbm-0:3.11.15-90002.4.15.1.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-devel-0:3.11.15-90002.4.15.1.aarch64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-devel-0:3.11.15-90002.4.15.1.ppc64le | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-devel-0:3.11.15-90002.4.15.1.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-devel-0:3.11.15-90002.4.15.1.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-editables-0:0.5-90002.3.3.2.noarch | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-exceptiongroup-0:1.2.2-90002.3.3.2.noarch | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-flit-core-0:3.12.0-90002.3.3.1.noarch | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-hatch-fancy-pypi-readme-0:25.1.0-90002.3.3.1.noarch | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-hatch-vcs-0:0.5.0-90002.3.3.1.noarch | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-hatchling-0:1.31.0-90002.3.3.1.noarch | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-idna-0:3.10-90002.3.6.2.noarch | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-iniconfig-0:2.1.0-90002.3.3.1.noarch | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-jinja2-0:3.1.6-90002.5.3.2.noarch | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-libs-0:3.11.15-90002.4.15.1.aarch64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-libs-0:3.11.15-90002.4.15.1.ppc64le | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-libs-0:3.11.15-90002.4.15.1.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-libs-0:3.11.15-90002.4.15.1.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-lxml-0:6.1.1-90002.3.9.2.aarch64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-lxml-0:6.1.1-90002.3.9.2.ppc64le | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-lxml-0:6.1.1-90002.3.9.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-lxml-0:6.1.1-90002.3.9.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-lxml-devel-0:6.1.1-90002.3.9.2.aarch64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-lxml-devel-0:6.1.1-90002.3.9.2.ppc64le | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-lxml-devel-0:6.1.1-90002.3.9.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-lxml-devel-0:6.1.1-90002.3.9.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-lxml-doc-0:6.1.1-90002.3.9.2.noarch | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-packaging-0:24.2-90002.3.3.1.noarch | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-pip-0:25.0.1-90002.3.3.1.noarch | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-pyasn1-0:0.6.3-90002.3.6.1.noarch | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-pyasn1-modules-0:0.4.2-90002.3.6.1.noarch | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-pyopenssl-0:23.2.0-90002.3.9.1.noarch | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-pyparsing-0:3.0.9-90002.3.6.1.noarch | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-requests-0:2.34.2-90002.4.6.1.noarch | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-testsuite-0:3.11.15-90002.4.15.1.aarch64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-testsuite-0:3.11.15-90002.4.15.1.ppc64le | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-testsuite-0:3.11.15-90002.4.15.1.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-testsuite-0:3.11.15-90002.4.15.1.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-tools-0:3.11.15-90002.4.15.1.aarch64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-tools-0:3.11.15-90002.4.15.1.ppc64le | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-tools-0:3.11.15-90002.4.15.1.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-tools-0:3.11.15-90002.4.15.1.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-tornado-0:6.3.2-90002.4.12.1.aarch64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-tornado-0:6.3.2-90002.4.12.1.ppc64le | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-tornado-0:6.3.2-90002.4.12.1.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-tornado-0:6.3.2-90002.4.12.1.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-urllib3-0:2.0.7-90002.3.6.1.noarch | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:saltbundlepy-websocket-client-0:1.9.0-90002.3.6.1.noarch | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:scap-security-guide-0:0.1.80-90002.3.12.1.noarch | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:scap-security-guide-debian-0:0.1.80-90002.3.12.1.noarch | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:scap-security-guide-redhat-0:0.1.80-90002.3.12.1.noarch | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:scap-security-guide-ubuntu-0:0.1.80-90002.3.12.1.noarch | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:spacecmd-0:5.2.10-90002.3.15.1.noarch | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:venv-salt-minion-0:3006.0-90002.5.22.1.aarch64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:venv-salt-minion-0:3006.0-90002.5.22.1.ppc64le | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:venv-salt-minion-0:3006.0-90002.5.22.1.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update:venv-salt-minion-0:3006.0-90002.5.22.1.x86_64 | — |
Vendor Fix
|
Threats
Impact
moderate
6.5 (Medium)
Affected products
Recommended
99 products, the same list as for
CVE-2024-22195
Threats
Impact
moderate
7.5 (High)
Affected products
Recommended
99 products, the same list as for
CVE-2024-22195
Threats
Impact
important
7.5 (High)
Affected products
Recommended
99 products, the same list as for
CVE-2024-22195
Threats
Impact
important
7.5 (High)
Affected products
Recommended
99 products, the same list as for
CVE-2024-22195
Threats
Impact
important
4.2 (Medium)
Affected products
Recommended
99 products, the same list as for
CVE-2024-22195
Threats
Impact
moderate
4.9 (Medium)
Affected products
Recommended
99 products, the same list as for
CVE-2024-22195
Threats
Impact
moderate
7.5 (High)
Affected products
Recommended
99 products, the same list as for
CVE-2024-22195
Threats
Impact
important
Affected products
Recommended
99 products, the same list as for
CVE-2024-22195
Threats
Impact
low
Affected products
Recommended
99 products, the same list as for
CVE-2024-22195
Threats
Impact
important
Affected products
Recommended
99 products, the same list as for
CVE-2024-22195
Threats
Impact
moderate
7.5 (High)
Affected products
Recommended
99 products, the same list as for
CVE-2024-22195
Threats
Impact
important
5.3 (Medium)
Affected products
Recommended
99 products, the same list as for
CVE-2024-22195
Threats
Impact
moderate
Affected products
Recommended
99 products, the same list as for
CVE-2024-22195
Threats
Impact
low
7.4 (High)
Affected products
Recommended
99 products, the same list as for
CVE-2024-22195
Threats
Impact
important
5.5 (Medium)
Affected products
Recommended
99 products, the same list as for
CVE-2024-22195
Threats
Impact
moderate
5.9 (Medium)
Affected products
Recommended
99 products, the same list as for
CVE-2024-22195
Threats
Impact
moderate
Affected products
Recommended
99 products, the same list as for
CVE-2024-22195
Threats
Impact
low
7.5 (High)
Affected products
Recommended
99 products, the same list as for
CVE-2024-22195
Threats
Impact
important
5.3 (Medium)
Affected products
Recommended
99 products, the same list as for
CVE-2024-22195
Threats
Impact
moderate
7.1 (High)
Affected products
Recommended
99 products, the same list as for
CVE-2024-22195
Threats
Impact
important
Affected products
Recommended
99 products, the same list as for
CVE-2024-22195
Threats
Impact
important
7.4 (High)
Affected products
Recommended
99 products, the same list as for
CVE-2024-22195
Threats
Impact
important
Affected products
Recommended
99 products, the same list as for
CVE-2024-22195
Threats
Impact
low
7.5 (High)
Affected products
Recommended
99 products, the same list as for
CVE-2024-22195
Threats
Impact
important
Affected products
Recommended
99 products, the same list as for
CVE-2024-22195
Threats
Impact
low
8.1 (High)
Affected products
Recommended
99 products, the same list as for
CVE-2024-22195
Threats
Impact
important
5.8 (Medium)
Affected products
Recommended
99 products, the same list as for
CVE-2024-22195
Threats
Impact
moderate
7.5 (High)
Affected products
Recommended
99 products, the same list as for
CVE-2024-22195
Threats
Impact
important
7.5 (High)
Affected products
Recommended
99 products, the same list as for
CVE-2024-22195
Threats
Impact
important
5.3 (Medium)
Affected products
Recommended
99 products, the same list as for
CVE-2024-22195
Threats
Impact
moderate
8.1 (High)
Affected products
Recommended
99 products, the same list as for
CVE-2024-22195
Threats
Impact
important
References
154 references
Loading 1.2 MB of JSON…
Loading…
Loading…
Experimental. This forecast is provided for visualization only and may change without notice. Do not use it for operational decisions.
Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
Loading…
The MITRE ATT&CK techniques below are AI-generated suggestions, inferred from the description of the
vulnerability by the CIRCL/vulnerability-attack-technique-classification-roberta-base
model, served locally by ML-Gateway.
They have not been verified by an analyst and are provided for guidance only.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Loading…
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.
Loading…