Information disclosure in SUSE Manager Client Tools for Ubuntu 20.04 - CVE-2024-22037

 

Information disclosure in SUSE Manager Client Tools for Ubuntu 20.04 - CVE-2024-22037

Published: February 17, 2025


Vulnerability identifier: #VU104016
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-22037
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to the uyuni-server-attestation systemd service uses the database_password environment variable to store password. A local user can obtain the password via systemd.


Affected software

SUSE Manager Client Tools for Ubuntu 20.04
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Desktop 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Proxy Extension
SUSE Manager Retail Branch Server Extension
SUSE Manager Server Extension
SUSE Manager Client Tools for SLE Micro
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
SUSE Manager Client Tools for RHEL, Liberty and Clones
SUSE Manager Client Tools for Debian
SUSE Manager Client Tools for SLE
SUSE Linux Enterprise Server for the Raspberry Pi
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise High Performance Computing
Basesystem Module
SUSE Package Hub 15
openSUSE Leap
SUSE Manager Client Tools for Ubuntu 22.04
SUSE Manager Client Tools for Ubuntu 24.04
mgradm-lang
mgrctl-zsh-completion
mgradm-bash-completion
mgradm-zsh-completion
mgrctl-bash-completion
mgrctl-lang
mgrctl-debuginfo
mgrctl
mgradm
mgradm-debuginfo
mgrpxy-zsh-completion
mgrpxy-bash-completion
mgrpxy-lang
mgrpxy-debuginfo
mgrpxy
mgrctl-fish-completion
scap-security-guide-redhat
scap-security-guide-ubuntu
firewalld-prometheus-config
dracut-saltboot
golang-github-prometheus-promu
supportutils-plugin-salt
golang-github-prometheus-prometheus
uyuni-storage-setup-server
uyuni-storage-setup-proxy
supportutils-plugin-susemanager-client
spacecmd
grafana
grafana-debuginfo
salt-common
salt-minion

How to mitigate CVE-2024-22037

Install updates from vendor's website.

mgradm-lang - update to 0.1.26-150500.3.12.2
mgrctl-zsh-completion - addressed in versions 0.1.26-150500.3.12.2, 0.1.28-1.14.1, 0.1.28-1.16.1, 0.1.28-2.6.2, 0.1.28-2.16.1, 0.1.28-2.16.2, 0.1.28-150000.1.16.1
mgradm-bash-completion - update to 0.1.26-150500.3.12.2
mgradm-zsh-completion - update to 0.1.26-150500.3.12.2
mgrctl-bash-completion - addressed in versions 0.1.26-150500.3.12.2, 0.1.28-1.14.1, 0.1.28-1.16.1, 0.1.28-2.6.2, 0.1.28-2.16.1, 0.1.28-2.16.2, 0.1.28-150000.1.16.1
mgrctl-lang - addressed in versions 0.1.26-150500.3.12.2, 0.1.28-150000.1.16.1
mgrctl-debuginfo - addressed in versions 0.1.26-150500.3.12.2, 0.1.28-1.14.1, 0.1.28-1.16.1, 0.1.28-150000.1.16.1
mgrctl - addressed in versions 0.1.26-150500.3.12.2, 0.1.28-1.14.1, 0.1.28-1.16.1, 0.1.28-2.6.2, 0.1.28-2.16.1, 0.1.28-2.16.2, 0.1.28-150000.1.16.1
mgradm - update to 0.1.26-150500.3.12.2
mgradm-debuginfo - update to 0.1.26-150500.3.12.2
mgrpxy-zsh-completion - update to 0.1.26-150500.3.12.2
mgrpxy-bash-completion - update to 0.1.26-150500.3.12.2
mgrpxy-lang - update to 0.1.26-150500.3.12.2
mgrpxy-debuginfo - update to 0.1.26-150500.3.12.2
mgrpxy - update to 0.1.26-150500.3.12.2
mgrctl-fish-completion - addressed in versions 0.1.28-2.6.2, 0.1.28-2.16.1, 0.1.28-2.16.2
scap-security-guide-redhat - update to 0.1.75-1.32.1
scap-security-guide-ubuntu - addressed in versions 0.1.75-2.34.2, 0.1.75-2.55.2
firewalld-prometheus-config - update to 0.1-150000.3.59.1
dracut-saltboot - update to 0.1.1728559936.c16d4fb-150000.1.56.1
golang-github-prometheus-promu - addressed in versions 0.17.0-1.24.1, 0.17.0-150000.3.24.1
supportutils-plugin-salt - addressed in versions 1.2.3-6.25.1, 1.2.3-150000.3.16.1
golang-github-prometheus-prometheus - addressed in versions 2.53.3-1.56.1, 2.53.3-150000.3.59.1
uyuni-storage-setup-server - update to 5.0.3-150500.12.6.4
uyuni-storage-setup-proxy - update to 5.0.3-150500.12.6.4
supportutils-plugin-susemanager-client - addressed in versions 5.0.4-6.33.1, 5.0.4-150000.3.27.1
spacecmd - addressed in versions 5.0.11-1.44.1, 5.0.11-2.6.1, 5.0.11-2.50.2, 5.0.11-2.95.2, 5.0.11-3.26.1, 5.0.11-38.153.1, 5.0.11-150000.3.130.1
grafana - addressed in versions 10.4.13-1.66.2, 10.4.13-150000.1.66.1
grafana-debuginfo - update to 10.4.13-150000.1.66.1
salt-common - update to 3006.0+ds-1+2.134.2
salt-minion - update to 3006.0+ds-1+2.134.2

External References

Related Security Bulletins