Path traversal in Uyuni SUSE Manager - CVE-2023-32189

 

Path traversal in Uyuni SUSE Manager - CVE-2023-32189

Published: February 20, 2024


Vulnerability identifier: #VU86618
CSH Severity: Medium
CVSS v4: 7.6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-32189
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform directory traversal attacks.

The vulnerability exists due to input validation error in SUSE Manager when processing directory traversal sequences in the private SSH key file name when creating a new user. A remote user can pass a specially crafted filename to the application and overwrite arbitrary files on the system.


Affected software

Uyuni SUSE Manager
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Proxy Module
SUSE Manager Server Module
openSUSE Leap
liberate-formula
saltboot-formula
inter-server-sync-debuginfo
inter-server-sync
jose4j
prometheus-formula
grafana-formula
prometheus-postgres_exporter
subscription-matcher
cobbler
mgr-daemon
uyuni-reportdb-schema
supportutils-plugin-susemanager
release-notes-susemanager-proxy
release-notes-susemanager
susemanager-sync-data
python3-spacewalk-client-tools
spacewalk-client-tools
spacewalk-check
python3-spacewalk-check
spacewalk-client-setup
python3-spacewalk-client-setup
spacewalk-utils-extras
spacewalk-utils
spacewalk-setup
python3-spacewalk-certs-tools
spacewalk-certs-tools
susemanager-schema
susemanager-schema-utility
spacecmd
spacewalk-backend-xml-export-libs
spacewalk-backend-iss-export
spacewalk-backend-package-push-server
spacewalk-backend-xmlrpc
spacewalk-backend-sql-postgresql
spacewalk-backend-sql
spacewalk-backend-config-files-tool
spacewalk-backend-server
spacewalk-backend-config-files-common
spacewalk-backend
spacewalk-backend-iss
spacewalk-backend-tools
spacewalk-backend-applet
spacewalk-backend-config-files
spacewalk-backend-app
susemanager-tools
susemanager
spacewalk-base-minimal-config
spacewalk-base
spacewalk-base-minimal
spacewalk-html
susemanager-sls
uyuni-config-modules
spacewalk-java
spacewalk-java-config
spacewalk-java-lib
spacewalk-taskomatic
spacewalk-java-postgresql
patterns-suma_proxy
patterns-suma_retail
patterns-suma_server
susemanager-docs_en-pdf
susemanager-docs_en
susemanager-build-keys-web
susemanager-build-keys

How to mitigate CVE-2023-32189

Install update from vendor's website.

Uyuni SUSE Manager - update to 4.1
liberate-formula - update to 0.1.0-150400.10.3.3
saltboot-formula - update to 0.1.1701196218.b6b8ca1-150400.3.15.3
inter-server-sync-debuginfo - update to 0.3.2-150400.3.27.5
inter-server-sync - update to 0.3.2-150400.3.27.5
jose4j - update to 0.5.1-150400.3.6.2
prometheus-formula - update to 0.8.0-150400.3.6.5
grafana-formula - update to 0.10.0-150400.3.15.5
prometheus-postgres_exporter - update to 0.10.1-150400.3.9.5
subscription-matcher - update to 0.35-150400.3.19.5
cobbler - update to 3.3.3-150400.5.39.5
mgr-daemon - update to 4.3.8-150400.3.12.5
uyuni-reportdb-schema - update to 4.3.9-150400.3.12.7
supportutils-plugin-susemanager - update to 4.3.10-150400.3.18.5
release-notes-susemanager-proxy - update to 4.3.11-150400.3.79.1
release-notes-susemanager - update to 4.3.11-150400.3.100.1
susemanager-sync-data - update to 4.3.16-150400.3.22.2
python3-spacewalk-client-tools - update to 4.3.18-150400.3.24.7
spacewalk-client-tools - update to 4.3.18-150400.3.24.7
spacewalk-check - update to 4.3.18-150400.3.24.7
python3-spacewalk-check - update to 4.3.18-150400.3.24.7
spacewalk-client-setup - update to 4.3.18-150400.3.24.7
python3-spacewalk-client-setup - update to 4.3.18-150400.3.24.7
spacewalk-utils-extras - update to 4.3.19-150400.3.21.5
spacewalk-utils - update to 4.3.19-150400.3.21.5
spacewalk-setup - update to 4.3.19-150400.3.30.5
python3-spacewalk-certs-tools - update to 4.3.22-150400.3.25.1
spacewalk-certs-tools - update to 4.3.22-150400.3.25.1
susemanager-schema - update to 4.3.24-150400.3.36.7
susemanager-schema-utility - update to 4.3.24-150400.3.36.7
spacecmd - update to 4.3.26-150400.3.33.5
spacewalk-backend-xml-export-libs - update to 4.3.27-150400.3.38.2
spacewalk-backend-iss-export - update to 4.3.27-150400.3.38.2
spacewalk-backend-package-push-server - update to 4.3.27-150400.3.38.2
spacewalk-backend-xmlrpc - update to 4.3.27-150400.3.38.2
spacewalk-backend-sql-postgresql - update to 4.3.27-150400.3.38.2
spacewalk-backend-sql - update to 4.3.27-150400.3.38.2
spacewalk-backend-config-files-tool - update to 4.3.27-150400.3.38.2
spacewalk-backend-server - update to 4.3.27-150400.3.38.2
spacewalk-backend-config-files-common - update to 4.3.27-150400.3.38.2
spacewalk-backend - update to 4.3.27-150400.3.38.2
spacewalk-backend-iss - update to 4.3.27-150400.3.38.2
spacewalk-backend-tools - update to 4.3.27-150400.3.38.2
spacewalk-backend-applet - update to 4.3.27-150400.3.38.2
spacewalk-backend-config-files - update to 4.3.27-150400.3.38.2
spacewalk-backend-app - update to 4.3.27-150400.3.38.2
susemanager-tools - update to 4.3.34-150400.3.45.5
susemanager - update to 4.3.34-150400.3.45.5
spacewalk-base-minimal-config - update to 4.3.37-150400.3.39.7
spacewalk-base - update to 4.3.37-150400.3.39.7
spacewalk-base-minimal - update to 4.3.37-150400.3.39.7
spacewalk-html - update to 4.3.37-150400.3.39.7
susemanager-sls - update to 4.3.40-150400.3.44.1
uyuni-config-modules - update to 4.3.40-150400.3.44.1
spacewalk-java - update to 4.3.71-150400.3.74.2
spacewalk-java-config - update to 4.3.71-150400.3.74.2
spacewalk-java-lib - update to 4.3.71-150400.3.74.2
spacewalk-taskomatic - update to 4.3.71-150400.3.74.2
spacewalk-java-postgresql - update to 4.3.71-150400.3.74.2
patterns-suma_proxy - update to 4.3-150400.5.9.5
patterns-suma_retail - update to 4.3-150400.5.9.5
patterns-suma_server - update to 4.3-150400.5.9.5
susemanager-docs_en-pdf - update to 4.3-150400.9.53.5
susemanager-docs_en - update to 4.3-150400.9.53.5
susemanager-build-keys-web - update to 15.4.10-150400.3.23.5
susemanager-build-keys - update to 15.4.10-150400.3.23.5

External References

Related Security Bulletins