Security Beta update for Salt

SUSE Security Update: Security Beta update for Salt
Announcement ID: SUSE-SU-2020:0538-1
Rating: moderate
References: #1163981
Cross-References:CVE-2019-17361
Affected Products:
  • SUSE Manager Tools 12-BETA

An update that fixes one vulnerability is now available.

Description:


This update fixes the following issues:
salt:

  • Fix 'os_family' grain for Astra Linux Common Edition
  • Update to Salt version 2019.2.3 (CVE-2019-17361) (bsc#1163981) See release notes: https://docs.saltstack.com/en/latest/topics/releases/2019.2.3.html
  • Enable passing grains to start event based on 'start_event_grains' configuration parameter

Patch Instructions:

To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

  • SUSE Manager Tools 12-BETA:
    zypper in -t patch SUSE-SLE-Manager-Tools-12-2020-538=1

Package List:

  • SUSE Manager Tools 12-BETA (aarch64 ppc64le s390x x86_64):
    • python2-salt-2019.2.3-49.9.1
    • python3-salt-2019.2.3-49.9.1
    • salt-2019.2.3-49.9.1
    • salt-doc-2019.2.3-49.9.1
    • salt-minion-2019.2.3-49.9.1

References: