suse-su-2025:02499-1
Vulnerability from csaf_suse
Published
2025-07-23 12:46
Modified
2025-07-23 12:46
Summary
Security update 5.0.5 for Multi-Linux Manager Salt Bundle
Notes
Title of the patch
Security update 5.0.5 for Multi-Linux Manager Salt Bundle
Description of the patch
This update fixes the following issues:
venv-salt-minion:
- Security issues fixed:
- CVE-2024-38822: Fixed Minion token validation (bsc#1244561)
- CVE-2024-38823: Fixed server vulnerability to replay attacks when not using a TLS encrypted transport (bsc#1244564)
- CVE-2024-38824: Fixed directory traversal vulnerability in recv_file method (bsc#1244565)
- CVE-2024-38825: Fixed salt.auth.pki module authentication issue (bsc#1244566)
- CVE-2025-22240: Fixed arbitrary directory creation or file deletion with GitFS (bsc#1244567)
- CVE-2025-22236: Fixed Minion event bus authorization bypass (bsc#1244568)
- CVE-2025-22241: Fixed the use of un-validated input in the VirtKey class (bsc#1244570)
- CVE-2025-22237: Fixed exploitation of the 'on demand' pillar functionality (bsc#1244571)
- CVE-2025-22238: Fixed the master's default cache vulnerability to a directory traversal attack (bsc#1244572)
- CVE-2025-22239: Fixed the arbitrary event injection on the Salt Master (bsc#1244574)
- CVE-2025-22242: Fixed a Denial of Service vulnerability through file read operation (bsc#1244575)
- CVE-2025-47287: Fixed a Denial of Service vulnerability in Tornado logging behavior (bsc#1243268)
- Other bugs fixed:
- Added subsystem filter to udev.exportdb (bsc#1236621)
- Fixed Ubuntu 24.04 test failures
- Fixed refresh of osrelease and related grains on Python 3.10+
- Fixed issue requiring proper Python flavor for dependencies
- Fixed VIRTUAL_ENV variable in activate file to point to actual path
- Fixed the bundle path in pyvenv.cfg
- Prevent tests failures when pygit2 is not present
Patchnames
SUSE-2025-2499,SUSE-EL-9-CLIENT-TOOLS-2025-2499
Terms of use
CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
{ "document": { "aggregate_severity": { "namespace": "https://www.suse.com/support/security/rating/", "text": "important" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright 2024 SUSE LLC. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "Security update 5.0.5 for Multi-Linux Manager Salt Bundle", "title": "Title of the patch" }, { "category": "description", "text": "This update fixes the following issues:\n\nvenv-salt-minion:\n \n- Security issues fixed:\n \n - CVE-2024-38822: Fixed Minion token validation (bsc#1244561)\n - CVE-2024-38823: Fixed server vulnerability to replay attacks when not using a TLS encrypted transport (bsc#1244564)\n - CVE-2024-38824: Fixed directory traversal vulnerability in recv_file method (bsc#1244565)\n - CVE-2024-38825: Fixed salt.auth.pki module authentication issue (bsc#1244566)\n - CVE-2025-22240: Fixed arbitrary directory creation or file deletion with GitFS (bsc#1244567)\n - CVE-2025-22236: Fixed Minion event bus authorization bypass (bsc#1244568)\n - CVE-2025-22241: Fixed the use of un-validated input in the VirtKey class (bsc#1244570)\n - CVE-2025-22237: Fixed exploitation of the \u0027on demand\u0027 pillar functionality (bsc#1244571)\n - CVE-2025-22238: Fixed the master\u0027s default cache vulnerability to a directory traversal attack (bsc#1244572)\n - CVE-2025-22239: Fixed the arbitrary event injection on the Salt Master (bsc#1244574) \n - CVE-2025-22242: Fixed a Denial of Service vulnerability through file read operation (bsc#1244575)\n - CVE-2025-47287: Fixed a Denial of Service vulnerability in Tornado logging behavior (bsc#1243268)\n\n- Other bugs fixed:\n\n - Added subsystem filter to udev.exportdb (bsc#1236621)\n - Fixed Ubuntu 24.04 test failures\n - Fixed refresh of osrelease and related grains on Python 3.10+\n - Fixed issue requiring proper Python flavor for dependencies\n - Fixed VIRTUAL_ENV variable in activate file to point to actual path\n - Fixed the bundle path in pyvenv.cfg\n - Prevent tests failures when pygit2 is not present\n\n", "title": "Description of the patch" }, { "category": "details", "text": "SUSE-2025-2499,SUSE-EL-9-CLIENT-TOOLS-2025-2499", "title": "Patchnames" }, { "category": "legal_disclaimer", "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).", "title": "Terms of use" } ], "publisher": { "category": "vendor", "contact_details": "https://www.suse.com/support/security/contact/", "name": "SUSE Product Security Team", "namespace": "https://www.suse.com/" }, "references": [ { "category": "external", "summary": "SUSE ratings", "url": "https://www.suse.com/support/security/rating/" }, { "category": "self", "summary": "URL of this CSAF notice", "url": "https://ftp.suse.com/pub/projects/security/csaf/suse-su-2025_02499-1.json" }, { "category": "self", "summary": "URL for SUSE-SU-2025:02499-1", "url": "https://www.suse.com/support/update/announcement/2025/suse-su-202502499-1/" }, { "category": "self", "summary": "E-Mail link for SUSE-SU-2025:02499-1", "url": "https://lists.suse.com/pipermail/sle-updates/2025-July/040875.html" }, { "category": "self", "summary": "SUSE Bug 1236621", "url": "https://bugzilla.suse.com/1236621" }, { "category": "self", "summary": "SUSE Bug 1243268", "url": "https://bugzilla.suse.com/1243268" }, { "category": "self", "summary": "SUSE Bug 1244561", "url": "https://bugzilla.suse.com/1244561" }, { "category": "self", "summary": "SUSE Bug 1244564", "url": "https://bugzilla.suse.com/1244564" }, { "category": "self", "summary": "SUSE Bug 1244565", "url": "https://bugzilla.suse.com/1244565" }, { "category": "self", "summary": "SUSE Bug 1244566", "url": "https://bugzilla.suse.com/1244566" }, { "category": "self", "summary": "SUSE Bug 1244567", "url": "https://bugzilla.suse.com/1244567" }, { "category": "self", "summary": "SUSE Bug 1244568", "url": "https://bugzilla.suse.com/1244568" }, { "category": "self", "summary": "SUSE Bug 1244570", "url": "https://bugzilla.suse.com/1244570" }, { "category": "self", "summary": "SUSE Bug 1244571", "url": "https://bugzilla.suse.com/1244571" }, { "category": "self", "summary": "SUSE Bug 1244572", "url": "https://bugzilla.suse.com/1244572" }, { "category": "self", "summary": "SUSE Bug 1244574", "url": "https://bugzilla.suse.com/1244574" }, { "category": "self", "summary": "SUSE Bug 1244575", "url": "https://bugzilla.suse.com/1244575" }, { "category": "self", "summary": "SUSE CVE CVE-2024-38822 page", "url": "https://www.suse.com/security/cve/CVE-2024-38822/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-38823 page", "url": "https://www.suse.com/security/cve/CVE-2024-38823/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-38824 page", "url": "https://www.suse.com/security/cve/CVE-2024-38824/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-38825 page", "url": "https://www.suse.com/security/cve/CVE-2024-38825/" }, { "category": "self", "summary": "SUSE CVE CVE-2025-22236 page", "url": "https://www.suse.com/security/cve/CVE-2025-22236/" }, { "category": "self", "summary": "SUSE CVE CVE-2025-22237 page", "url": "https://www.suse.com/security/cve/CVE-2025-22237/" }, { "category": "self", "summary": "SUSE CVE CVE-2025-22238 page", "url": "https://www.suse.com/security/cve/CVE-2025-22238/" }, { "category": "self", "summary": "SUSE CVE CVE-2025-22239 page", "url": "https://www.suse.com/security/cve/CVE-2025-22239/" }, { "category": "self", "summary": "SUSE CVE CVE-2025-22240 page", "url": "https://www.suse.com/security/cve/CVE-2025-22240/" }, { "category": "self", "summary": "SUSE CVE CVE-2025-22241 page", "url": "https://www.suse.com/security/cve/CVE-2025-22241/" }, { "category": "self", "summary": "SUSE CVE CVE-2025-22242 page", "url": "https://www.suse.com/security/cve/CVE-2025-22242/" }, { "category": "self", "summary": "SUSE CVE CVE-2025-47287 page", "url": "https://www.suse.com/security/cve/CVE-2025-47287/" } ], "title": "Security update 5.0.5 for Multi-Linux Manager Salt Bundle", "tracking": { "current_release_date": "2025-07-23T12:46:00Z", "generator": { "date": "2025-07-23T12:46:00Z", "engine": { "name": "cve-database.git:bin/generate-csaf.pl", "version": "1" } }, "id": "SUSE-SU-2025:02499-1", "initial_release_date": "2025-07-23T12:46:00Z", "revision_history": [ { "date": "2025-07-23T12:46:00Z", "number": "1", "summary": "Current version" } ], "status": "final", "version": "1" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_version", "name": "saltbundlepy-3.11.11-1.32.1.aarch64", "product": { "name": "saltbundlepy-3.11.11-1.32.1.aarch64", "product_id": "saltbundlepy-3.11.11-1.32.1.aarch64" } }, { "category": "product_version", "name": "saltbundlepy-base-3.11.11-1.32.1.aarch64", "product": { "name": "saltbundlepy-base-3.11.11-1.32.1.aarch64", "product_id": "saltbundlepy-base-3.11.11-1.32.1.aarch64" } }, { "category": "product_version", "name": "saltbundlepy-curses-3.11.11-1.32.1.aarch64", "product": { "name": "saltbundlepy-curses-3.11.11-1.32.1.aarch64", "product_id": "saltbundlepy-curses-3.11.11-1.32.1.aarch64" } }, { "category": "product_version", "name": "saltbundlepy-cython-0.29.37-1.12.2.aarch64", "product": { "name": "saltbundlepy-cython-0.29.37-1.12.2.aarch64", "product_id": "saltbundlepy-cython-0.29.37-1.12.2.aarch64" } }, { "category": "product_version", "name": "saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "product": { "name": "saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "product_id": "saltbundlepy-dbm-3.11.11-1.32.1.aarch64" } }, { "category": "product_version", "name": "saltbundlepy-devel-3.11.11-1.32.1.aarch64", "product": { "name": "saltbundlepy-devel-3.11.11-1.32.1.aarch64", "product_id": "saltbundlepy-devel-3.11.11-1.32.1.aarch64" } }, { "category": "product_version", "name": "saltbundlepy-libs-3.11.11-1.32.1.aarch64", "product": { "name": "saltbundlepy-libs-3.11.11-1.32.1.aarch64", "product_id": "saltbundlepy-libs-3.11.11-1.32.1.aarch64" } }, { "category": "product_version", "name": "saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "product": { "name": "saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "product_id": "saltbundlepy-lxml-4.9.4-1.21.1.aarch64" } }, { "category": "product_version", "name": "saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "product": { "name": "saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "product_id": "saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64" } }, { "category": "product_version", "name": "saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "product": { "name": "saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "product_id": "saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64" } }, { "category": "product_version", "name": "saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "product": { "name": "saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "product_id": "saltbundlepy-msgpack-1.0.7-1.14.1.aarch64" } }, { "category": "product_version", "name": "saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "product": { "name": "saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "product_id": "saltbundlepy-testsuite-3.11.11-1.32.1.aarch64" } }, { "category": "product_version", "name": "saltbundlepy-tools-3.11.11-1.32.1.aarch64", "product": { "name": "saltbundlepy-tools-3.11.11-1.32.1.aarch64", "product_id": "saltbundlepy-tools-3.11.11-1.32.1.aarch64" } }, { "category": "product_version", "name": "saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "product": { "name": "saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "product_id": "saltbundlepy-tornado-6.3.2-1.12.2.aarch64" } }, { "category": "product_version", "name": "venv-salt-minion-3006.0-1.59.1.aarch64", "product": { "name": "venv-salt-minion-3006.0-1.59.1.aarch64", "product_id": "venv-salt-minion-3006.0-1.59.1.aarch64" } } ], "category": "architecture", "name": "aarch64" }, { "branches": [ { "category": "product_version", "name": "saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "product": { "name": "saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "product_id": "saltbundlepy-jinja2-3.1.2-1.12.2.noarch" } }, { "category": "product_version", "name": "saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "product": { "name": "saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "product_id": "saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch" } }, { "category": "product_version", "name": "saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "product": { "name": "saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "product_id": "saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch" } }, { "category": "product_version", "name": "saltbundlepy-ply-3.11-1.8.1.noarch", "product": { "name": "saltbundlepy-ply-3.11-1.8.1.noarch", "product_id": "saltbundlepy-ply-3.11-1.8.1.noarch" } }, { "category": "product_version", "name": "saltbundlepy-ply-doc-3.11-1.8.1.noarch", "product": { "name": "saltbundlepy-ply-doc-3.11-1.8.1.noarch", "product_id": "saltbundlepy-ply-doc-3.11-1.8.1.noarch" } }, { "category": "product_version", "name": "saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "product": { "name": "saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "product_id": "saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch" } } ], "category": "architecture", "name": "noarch" }, { "branches": [ { "category": "product_version", "name": "saltbundlepy-3.11.11-1.32.1.ppc64le", "product": { "name": "saltbundlepy-3.11.11-1.32.1.ppc64le", "product_id": "saltbundlepy-3.11.11-1.32.1.ppc64le" } }, { "category": "product_version", "name": "saltbundlepy-base-3.11.11-1.32.1.ppc64le", "product": { "name": "saltbundlepy-base-3.11.11-1.32.1.ppc64le", "product_id": "saltbundlepy-base-3.11.11-1.32.1.ppc64le" } }, { "category": "product_version", "name": "saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "product": { "name": "saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "product_id": "saltbundlepy-curses-3.11.11-1.32.1.ppc64le" } }, { "category": "product_version", "name": "saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "product": { "name": "saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "product_id": "saltbundlepy-cython-0.29.37-1.12.2.ppc64le" } }, { "category": "product_version", "name": "saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "product": { "name": "saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "product_id": "saltbundlepy-dbm-3.11.11-1.32.1.ppc64le" } }, { "category": "product_version", "name": "saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "product": { "name": "saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "product_id": "saltbundlepy-devel-3.11.11-1.32.1.ppc64le" } }, { "category": "product_version", "name": "saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "product": { "name": "saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "product_id": "saltbundlepy-libs-3.11.11-1.32.1.ppc64le" } }, { "category": "product_version", "name": "saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "product": { "name": "saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "product_id": "saltbundlepy-lxml-4.9.4-1.21.1.ppc64le" } }, { "category": "product_version", "name": "saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "product": { "name": "saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "product_id": "saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le" } }, { "category": "product_version", "name": "saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "product": { "name": "saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "product_id": "saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le" } }, { "category": "product_version", "name": "saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "product": { "name": "saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "product_id": "saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le" } }, { "category": "product_version", "name": "saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "product": { "name": "saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "product_id": "saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le" } }, { "category": "product_version", "name": "saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "product": { "name": "saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "product_id": "saltbundlepy-tools-3.11.11-1.32.1.ppc64le" } }, { "category": "product_version", "name": "saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "product": { "name": "saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "product_id": "saltbundlepy-tornado-6.3.2-1.12.2.ppc64le" } }, { "category": "product_version", "name": "venv-salt-minion-3006.0-1.59.1.ppc64le", "product": { "name": "venv-salt-minion-3006.0-1.59.1.ppc64le", "product_id": "venv-salt-minion-3006.0-1.59.1.ppc64le" } } ], "category": "architecture", "name": "ppc64le" }, { "branches": [ { "category": "product_version", "name": "saltbundlepy-3.11.11-1.32.1.s390x", "product": { "name": "saltbundlepy-3.11.11-1.32.1.s390x", "product_id": "saltbundlepy-3.11.11-1.32.1.s390x" } }, { "category": "product_version", "name": "saltbundlepy-base-3.11.11-1.32.1.s390x", "product": { "name": "saltbundlepy-base-3.11.11-1.32.1.s390x", "product_id": "saltbundlepy-base-3.11.11-1.32.1.s390x" } }, { "category": "product_version", "name": "saltbundlepy-curses-3.11.11-1.32.1.s390x", "product": { "name": "saltbundlepy-curses-3.11.11-1.32.1.s390x", "product_id": "saltbundlepy-curses-3.11.11-1.32.1.s390x" } }, { "category": "product_version", "name": "saltbundlepy-cython-0.29.37-1.12.2.s390x", "product": { "name": "saltbundlepy-cython-0.29.37-1.12.2.s390x", "product_id": "saltbundlepy-cython-0.29.37-1.12.2.s390x" } }, { "category": "product_version", "name": "saltbundlepy-dbm-3.11.11-1.32.1.s390x", "product": { "name": "saltbundlepy-dbm-3.11.11-1.32.1.s390x", "product_id": "saltbundlepy-dbm-3.11.11-1.32.1.s390x" } }, { "category": "product_version", "name": "saltbundlepy-devel-3.11.11-1.32.1.s390x", "product": { "name": "saltbundlepy-devel-3.11.11-1.32.1.s390x", "product_id": "saltbundlepy-devel-3.11.11-1.32.1.s390x" } }, { "category": "product_version", "name": "saltbundlepy-libs-3.11.11-1.32.1.s390x", "product": { "name": "saltbundlepy-libs-3.11.11-1.32.1.s390x", "product_id": "saltbundlepy-libs-3.11.11-1.32.1.s390x" } }, { "category": "product_version", "name": "saltbundlepy-lxml-4.9.4-1.21.1.s390x", "product": { "name": "saltbundlepy-lxml-4.9.4-1.21.1.s390x", "product_id": "saltbundlepy-lxml-4.9.4-1.21.1.s390x" } }, { "category": "product_version", "name": "saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "product": { "name": "saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "product_id": "saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x" } }, { "category": "product_version", "name": "saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "product": { "name": "saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "product_id": "saltbundlepy-m2crypto-0.45.1-1.12.1.s390x" } }, { "category": "product_version", "name": "saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "product": { "name": "saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "product_id": "saltbundlepy-msgpack-1.0.7-1.14.1.s390x" } }, { "category": "product_version", "name": "saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "product": { "name": "saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "product_id": "saltbundlepy-testsuite-3.11.11-1.32.1.s390x" } }, { "category": "product_version", "name": "saltbundlepy-tools-3.11.11-1.32.1.s390x", "product": { "name": "saltbundlepy-tools-3.11.11-1.32.1.s390x", "product_id": "saltbundlepy-tools-3.11.11-1.32.1.s390x" } }, { "category": "product_version", "name": "saltbundlepy-tornado-6.3.2-1.12.2.s390x", "product": { "name": "saltbundlepy-tornado-6.3.2-1.12.2.s390x", "product_id": "saltbundlepy-tornado-6.3.2-1.12.2.s390x" } }, { "category": "product_version", "name": "venv-salt-minion-3006.0-1.59.1.s390x", "product": { "name": "venv-salt-minion-3006.0-1.59.1.s390x", "product_id": "venv-salt-minion-3006.0-1.59.1.s390x" } } ], "category": "architecture", "name": "s390x" }, { "branches": [ { "category": "product_version", "name": "saltbundlepy-3.11.11-1.32.1.x86_64", "product": { "name": "saltbundlepy-3.11.11-1.32.1.x86_64", "product_id": "saltbundlepy-3.11.11-1.32.1.x86_64" } }, { "category": "product_version", "name": "saltbundlepy-base-3.11.11-1.32.1.x86_64", "product": { "name": "saltbundlepy-base-3.11.11-1.32.1.x86_64", "product_id": "saltbundlepy-base-3.11.11-1.32.1.x86_64" } }, { "category": "product_version", "name": "saltbundlepy-curses-3.11.11-1.32.1.x86_64", "product": { "name": "saltbundlepy-curses-3.11.11-1.32.1.x86_64", "product_id": "saltbundlepy-curses-3.11.11-1.32.1.x86_64" } }, { "category": "product_version", "name": "saltbundlepy-cython-0.29.37-1.12.2.x86_64", "product": { "name": "saltbundlepy-cython-0.29.37-1.12.2.x86_64", "product_id": "saltbundlepy-cython-0.29.37-1.12.2.x86_64" } }, { "category": "product_version", "name": "saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "product": { "name": "saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "product_id": "saltbundlepy-dbm-3.11.11-1.32.1.x86_64" } }, { "category": "product_version", "name": "saltbundlepy-devel-3.11.11-1.32.1.x86_64", "product": { "name": "saltbundlepy-devel-3.11.11-1.32.1.x86_64", "product_id": "saltbundlepy-devel-3.11.11-1.32.1.x86_64" } }, { "category": "product_version", "name": "saltbundlepy-libs-3.11.11-1.32.1.x86_64", "product": { "name": "saltbundlepy-libs-3.11.11-1.32.1.x86_64", "product_id": "saltbundlepy-libs-3.11.11-1.32.1.x86_64" } }, { "category": "product_version", "name": "saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "product": { "name": "saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "product_id": "saltbundlepy-lxml-4.9.4-1.21.1.x86_64" } }, { "category": "product_version", "name": "saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "product": { "name": "saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "product_id": "saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64" } }, { "category": "product_version", "name": "saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "product": { "name": "saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "product_id": "saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64" } }, { "category": "product_version", "name": "saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "product": { "name": "saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "product_id": "saltbundlepy-msgpack-1.0.7-1.14.1.x86_64" } }, { "category": "product_version", "name": "saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "product": { "name": "saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "product_id": "saltbundlepy-testsuite-3.11.11-1.32.1.x86_64" } }, { "category": "product_version", "name": "saltbundlepy-tools-3.11.11-1.32.1.x86_64", "product": { "name": "saltbundlepy-tools-3.11.11-1.32.1.x86_64", "product_id": "saltbundlepy-tools-3.11.11-1.32.1.x86_64" } }, { "category": "product_version", "name": "saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "product": { "name": "saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "product_id": "saltbundlepy-tornado-6.3.2-1.12.2.x86_64" } }, { "category": "product_version", "name": "venv-salt-minion-3006.0-1.59.1.x86_64", "product": { "name": "venv-salt-minion-3006.0-1.59.1.x86_64", "product_id": "venv-salt-minion-3006.0-1.59.1.x86_64" } } ], "category": "architecture", "name": "x86_64" }, { "branches": [ { "category": "product_name", "name": "SUSE:EL-9:Update:Products:SaltBundle:Update", "product": { "name": "SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update" } }, { "category": "product_name", "name": "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS", "product": { "name": "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS", "product_id": "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS" } } ], "category": "product_family", "name": "SUSE Linux Enterprise" } ], "category": "vendor", "name": "SUSE" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-3.11.11-1.32.1.aarch64 as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64" }, "product_reference": "saltbundlepy-3.11.11-1.32.1.aarch64", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-3.11.11-1.32.1.ppc64le as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le" }, "product_reference": "saltbundlepy-3.11.11-1.32.1.ppc64le", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-3.11.11-1.32.1.s390x as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x" }, "product_reference": "saltbundlepy-3.11.11-1.32.1.s390x", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-3.11.11-1.32.1.x86_64 as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64" }, "product_reference": "saltbundlepy-3.11.11-1.32.1.x86_64", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-base-3.11.11-1.32.1.aarch64 as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64" }, "product_reference": "saltbundlepy-base-3.11.11-1.32.1.aarch64", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-base-3.11.11-1.32.1.ppc64le as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le" }, "product_reference": "saltbundlepy-base-3.11.11-1.32.1.ppc64le", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-base-3.11.11-1.32.1.s390x as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x" }, "product_reference": "saltbundlepy-base-3.11.11-1.32.1.s390x", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-base-3.11.11-1.32.1.x86_64 as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64" }, "product_reference": "saltbundlepy-base-3.11.11-1.32.1.x86_64", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-curses-3.11.11-1.32.1.aarch64 as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64" }, "product_reference": "saltbundlepy-curses-3.11.11-1.32.1.aarch64", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-curses-3.11.11-1.32.1.ppc64le as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le" }, "product_reference": "saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-curses-3.11.11-1.32.1.s390x as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x" }, "product_reference": "saltbundlepy-curses-3.11.11-1.32.1.s390x", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-curses-3.11.11-1.32.1.x86_64 as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64" }, "product_reference": "saltbundlepy-curses-3.11.11-1.32.1.x86_64", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-cython-0.29.37-1.12.2.aarch64 as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64" }, "product_reference": "saltbundlepy-cython-0.29.37-1.12.2.aarch64", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-cython-0.29.37-1.12.2.ppc64le as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le" }, "product_reference": "saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-cython-0.29.37-1.12.2.s390x as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x" }, "product_reference": "saltbundlepy-cython-0.29.37-1.12.2.s390x", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-cython-0.29.37-1.12.2.x86_64 as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64" }, "product_reference": "saltbundlepy-cython-0.29.37-1.12.2.x86_64", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-dbm-3.11.11-1.32.1.aarch64 as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64" }, "product_reference": "saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-dbm-3.11.11-1.32.1.ppc64le as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le" }, "product_reference": "saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-dbm-3.11.11-1.32.1.s390x as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x" }, "product_reference": "saltbundlepy-dbm-3.11.11-1.32.1.s390x", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-dbm-3.11.11-1.32.1.x86_64 as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64" }, "product_reference": "saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-devel-3.11.11-1.32.1.aarch64 as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64" }, "product_reference": "saltbundlepy-devel-3.11.11-1.32.1.aarch64", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-devel-3.11.11-1.32.1.ppc64le as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le" }, "product_reference": "saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-devel-3.11.11-1.32.1.s390x as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x" }, "product_reference": "saltbundlepy-devel-3.11.11-1.32.1.s390x", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-devel-3.11.11-1.32.1.x86_64 as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64" }, "product_reference": "saltbundlepy-devel-3.11.11-1.32.1.x86_64", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-jinja2-3.1.2-1.12.2.noarch as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch" }, "product_reference": "saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-libs-3.11.11-1.32.1.aarch64 as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64" }, "product_reference": "saltbundlepy-libs-3.11.11-1.32.1.aarch64", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-libs-3.11.11-1.32.1.ppc64le as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le" }, "product_reference": "saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-libs-3.11.11-1.32.1.s390x as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x" }, "product_reference": "saltbundlepy-libs-3.11.11-1.32.1.s390x", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-libs-3.11.11-1.32.1.x86_64 as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64" }, "product_reference": "saltbundlepy-libs-3.11.11-1.32.1.x86_64", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-lxml-4.9.4-1.21.1.aarch64 as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64" }, "product_reference": "saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-lxml-4.9.4-1.21.1.ppc64le as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le" }, "product_reference": "saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-lxml-4.9.4-1.21.1.s390x as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x" }, "product_reference": "saltbundlepy-lxml-4.9.4-1.21.1.s390x", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-lxml-4.9.4-1.21.1.x86_64 as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64" }, "product_reference": "saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64 as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64" }, "product_reference": "saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le" }, "product_reference": "saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x" }, "product_reference": "saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64 as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64" }, "product_reference": "saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch" }, "product_reference": "saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64 as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64" }, "product_reference": "saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le" }, "product_reference": "saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-m2crypto-0.45.1-1.12.1.s390x as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x" }, "product_reference": "saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64 as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64" }, "product_reference": "saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch" }, "product_reference": "saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-msgpack-1.0.7-1.14.1.aarch64 as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64" }, "product_reference": "saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le" }, "product_reference": "saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-msgpack-1.0.7-1.14.1.s390x as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x" }, "product_reference": "saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-msgpack-1.0.7-1.14.1.x86_64 as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64" }, "product_reference": "saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-ply-3.11-1.8.1.noarch as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch" }, "product_reference": "saltbundlepy-ply-3.11-1.8.1.noarch", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-ply-doc-3.11-1.8.1.noarch as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch" }, "product_reference": "saltbundlepy-ply-doc-3.11-1.8.1.noarch", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-testsuite-3.11.11-1.32.1.aarch64 as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64" }, "product_reference": "saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le" }, "product_reference": "saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-testsuite-3.11.11-1.32.1.s390x as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x" }, "product_reference": "saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-testsuite-3.11.11-1.32.1.x86_64 as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64" }, "product_reference": "saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-tools-3.11.11-1.32.1.aarch64 as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64" }, "product_reference": "saltbundlepy-tools-3.11.11-1.32.1.aarch64", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-tools-3.11.11-1.32.1.ppc64le as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le" }, "product_reference": "saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-tools-3.11.11-1.32.1.s390x as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x" }, "product_reference": "saltbundlepy-tools-3.11.11-1.32.1.s390x", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-tools-3.11.11-1.32.1.x86_64 as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64" }, "product_reference": "saltbundlepy-tools-3.11.11-1.32.1.x86_64", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-tornado-6.3.2-1.12.2.aarch64 as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64" }, "product_reference": "saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-tornado-6.3.2-1.12.2.ppc64le as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le" }, "product_reference": "saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-tornado-6.3.2-1.12.2.s390x as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x" }, "product_reference": "saltbundlepy-tornado-6.3.2-1.12.2.s390x", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-tornado-6.3.2-1.12.2.x86_64 as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64" }, "product_reference": "saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch" }, "product_reference": "saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "venv-salt-minion-3006.0-1.59.1.aarch64 as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64" }, "product_reference": "venv-salt-minion-3006.0-1.59.1.aarch64", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "venv-salt-minion-3006.0-1.59.1.ppc64le as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le" }, "product_reference": "venv-salt-minion-3006.0-1.59.1.ppc64le", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "venv-salt-minion-3006.0-1.59.1.s390x as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x" }, "product_reference": "venv-salt-minion-3006.0-1.59.1.s390x", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "venv-salt-minion-3006.0-1.59.1.x86_64 as component of SUSE:EL-9:Update:Products:SaltBundle:Update", "product_id": "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" }, "product_reference": "venv-salt-minion-3006.0-1.59.1.x86_64", "relates_to_product_reference": "SUSE:EL-9:Update:Products:SaltBundle:Update" }, { "category": "default_component_of", "full_product_name": { "name": "venv-salt-minion-3006.0-1.59.1.aarch64 as component of SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS", "product_id": "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64" }, "product_reference": "venv-salt-minion-3006.0-1.59.1.aarch64", "relates_to_product_reference": "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS" }, { "category": "default_component_of", "full_product_name": { "name": "venv-salt-minion-3006.0-1.59.1.ppc64le as component of SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS", "product_id": "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le" }, "product_reference": "venv-salt-minion-3006.0-1.59.1.ppc64le", "relates_to_product_reference": "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS" }, { "category": "default_component_of", "full_product_name": { "name": "venv-salt-minion-3006.0-1.59.1.s390x as component of SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS", "product_id": "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x" }, "product_reference": "venv-salt-minion-3006.0-1.59.1.s390x", "relates_to_product_reference": "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS" }, { "category": "default_component_of", "full_product_name": { "name": "venv-salt-minion-3006.0-1.59.1.x86_64 as component of SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS", "product_id": "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64" }, "product_reference": "venv-salt-minion-3006.0-1.59.1.x86_64", "relates_to_product_reference": "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS" } ] }, "vulnerabilities": [ { "cve": "CVE-2024-38822", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-38822" } ], "notes": [ { "category": "general", "text": "Multiple methods in the salt master skip minion token validation. Therefore a misbehaving minion can impersonate another minion.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-38822", "url": "https://www.suse.com/security/cve/CVE-2024-38822" }, { "category": "external", "summary": "SUSE Bug 1244561 for CVE-2024-38822", "url": "https://bugzilla.suse.com/1244561" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 2.7, "baseSeverity": "LOW", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N", "version": "3.1" }, "products": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-07-23T12:46:00Z", "details": "low" } ], "title": "CVE-2024-38822" }, { "cve": "CVE-2024-38823", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-38823" } ], "notes": [ { "category": "general", "text": "Salt\u0027s request server is vulnerable to replay attacks when not using a TLS encrypted transport.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-38823", "url": "https://www.suse.com/security/cve/CVE-2024-38823" }, { "category": "external", "summary": "SUSE Bug 1244564 for CVE-2024-38823", "url": "https://bugzilla.suse.com/1244564" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.9, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N", "version": "3.1" }, "products": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-07-23T12:46:00Z", "details": "moderate" } ], "title": "CVE-2024-38823" }, { "cve": "CVE-2024-38824", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-38824" } ], "notes": [ { "category": "general", "text": "Directory traversal vulnerability in recv_file method allows arbitrary files to be written to the master cache directory.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-38824", "url": "https://www.suse.com/security/cve/CVE-2024-38824" }, { "category": "external", "summary": "SUSE Bug 1244565 for CVE-2024-38824", "url": "https://bugzilla.suse.com/1244565" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.6, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N", "version": "3.1" }, "products": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-07-23T12:46:00Z", "details": "critical" } ], "title": "CVE-2024-38824" }, { "cve": "CVE-2024-38825", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-38825" } ], "notes": [ { "category": "general", "text": "The salt.auth.pki module does not properly authenticate callers. The \"password\" field contains a public certificate which is validated against a CA certificate by the module. This is not pki authentication, as the caller does not need access to the corresponding private key for the authentication attempt to be accepted.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-38825", "url": "https://www.suse.com/security/cve/CVE-2024-38825" }, { "category": "external", "summary": "SUSE Bug 1244566 for CVE-2024-38825", "url": "https://bugzilla.suse.com/1244566" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.4, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N", "version": "3.1" }, "products": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-07-23T12:46:00Z", "details": "moderate" } ], "title": "CVE-2024-38825" }, { "cve": "CVE-2025-22236", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2025-22236" } ], "notes": [ { "category": "general", "text": "Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to execute a job on other minions (\u003e= 3007.0).", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2025-22236", "url": "https://www.suse.com/security/cve/CVE-2025-22236" }, { "category": "external", "summary": "SUSE Bug 1244568 for CVE-2025-22236", "url": "https://bugzilla.suse.com/1244568" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.1, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L", "version": "3.1" }, "products": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-07-23T12:46:00Z", "details": "important" } ], "title": "CVE-2025-22236" }, { "cve": "CVE-2025-22237", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2025-22237" } ], "notes": [ { "category": "general", "text": "An attacker with access to a minion key can exploit the \u0027on demand\u0027 pillar functionality with a specially crafted git url which could cause and arbitrary command to be run on the master with the same privileges as the master process.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2025-22237", "url": "https://www.suse.com/security/cve/CVE-2025-22237" }, { "category": "external", "summary": "SUSE Bug 1244571 for CVE-2025-22237", "url": "https://bugzilla.suse.com/1244571" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.7, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-07-23T12:46:00Z", "details": "moderate" } ], "title": "CVE-2025-22237" }, { "cve": "CVE-2025-22238", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2025-22238" } ], "notes": [ { "category": "general", "text": "Directory traversal attack in minion file cache creation. The master\u0027s default cache is vulnerable to a directory traversal attack. Which could be leveraged to write or overwrite \u0027cache\u0027 files outside of the cache directory.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2025-22238", "url": "https://www.suse.com/security/cve/CVE-2025-22238" }, { "category": "external", "summary": "SUSE Bug 1244572 for CVE-2025-22238", "url": "https://bugzilla.suse.com/1244572" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.4, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N", "version": "3.1" }, "products": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-07-23T12:46:00Z", "details": "moderate" } ], "title": "CVE-2025-22238" }, { "cve": "CVE-2025-22239", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2025-22239" } ], "notes": [ { "category": "general", "text": "Arbitrary event injection on Salt Master. The master\u0027s \"_minion_event\" method can be used by and authorized minion to send arbitrary events onto the master\u0027s event bus.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2025-22239", "url": "https://www.suse.com/security/cve/CVE-2025-22239" }, { "category": "external", "summary": "SUSE Bug 1244574 for CVE-2025-22239", "url": "https://bugzilla.suse.com/1244574" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.1, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L", "version": "3.1" }, "products": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-07-23T12:46:00Z", "details": "important" } ], "title": "CVE-2025-22239" }, { "cve": "CVE-2025-22240", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2025-22240" } ], "notes": [ { "category": "general", "text": "Arbitrary directory creation or file deletion. In the find_file method of the GitFS class, a path is created using os.path.join using unvalidated input from the \"tgt_env\" variable. This can be exploited by an attacker to delete any file on the Master\u0027s process has permissions to.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2025-22240", "url": "https://www.suse.com/security/cve/CVE-2025-22240" }, { "category": "external", "summary": "SUSE Bug 1244567 for CVE-2025-22240", "url": "https://bugzilla.suse.com/1244567" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-07-23T12:46:00Z", "details": "moderate" } ], "title": "CVE-2025-22240" }, { "cve": "CVE-2025-22241", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2025-22241" } ], "notes": [ { "category": "general", "text": "File contents overwrite the VirtKey class is called when \"on-demand pillar\" data is requested and uses un-validated input to create paths to the \"pki directory\". The functionality is used to auto-accept Minion authentication keys based on a pre-placed \"authorization file\" at a specific location and is present in the default configuration.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2025-22241", "url": "https://www.suse.com/security/cve/CVE-2025-22241" }, { "category": "external", "summary": "SUSE Bug 1244570 for CVE-2025-22241", "url": "https://bugzilla.suse.com/1244570" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.6, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N", "version": "3.1" }, "products": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-07-23T12:46:00Z", "details": "moderate" } ], "title": "CVE-2025-22241" }, { "cve": "CVE-2025-22242", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2025-22242" } ], "notes": [ { "category": "general", "text": "Worker process denial of service through file read operation. .A vulnerability exists in the Master\u0027s \"pub_ret\" method which is exposed to all minions. The un-sanitized input value \"jid\" is used to construct a path which is then opened for reading. An attacker could exploit this vulnerabilities by attempting to read from a filename that will not return any data, e.g. by targeting a pipe node on the proc file system.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2025-22242", "url": "https://www.suse.com/security/cve/CVE-2025-22242" }, { "category": "external", "summary": "SUSE Bug 1244575 for CVE-2025-22242", "url": "https://bugzilla.suse.com/1244575" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.4, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-07-23T12:46:00Z", "details": "moderate" } ], "title": "CVE-2025-22242" }, { "cve": "CVE-2025-47287", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2025-47287" } ], "notes": [ { "category": "general", "text": "Tornado is a Python web framework and asynchronous networking library. When Tornado\u0027s ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous. All versions of Tornado prior to 6.5.0 are affected. The vulnerable parser is enabled by default. Upgrade to Tornado version 6.50 to receive a patch. As a workaround, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2025-47287", "url": "https://www.suse.com/security/cve/CVE-2025-47287" }, { "category": "external", "summary": "SUSE Bug 1243268 for CVE-2025-47287", "url": "https://bugzilla.suse.com/1243268" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.5, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS:venv-salt-minion-3006.0-1.59.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-base-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-curses-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-cython-0.29.37-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-dbm-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-devel-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-jinja2-3.1.2-1.12.2.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-libs-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-devel-4.9.4-1.21.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-lxml-doc-4.9.4-1.21.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-0.45.1-1.12.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-m2crypto-doc-0.45.1-1.12.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-msgpack-1.0.7-1.14.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-ply-doc-3.11-1.8.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-testsuite-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tools-3.11.11-1.32.1.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-tornado-6.3.2-1.12.2.x86_64", "SUSE:EL-9:Update:Products:SaltBundle:Update:saltbundlepy-zypp-plugin-0.6.5-1.11.1.noarch", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.aarch64", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.ppc64le", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.s390x", "SUSE:EL-9:Update:Products:SaltBundle:Update:venv-salt-minion-3006.0-1.59.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-07-23T12:46:00Z", "details": "important" } ], "title": "CVE-2025-47287" } ] }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…