{"affected":[{"ecosystem_specific":{"binaries":[{"cobbler":"3.3.7-bp155.2.3.2","cobbler-tests":"3.3.7-bp155.2.3.2","cobbler-tests-containers":"3.3.7-bp155.2.3.2"}]},"package":{"ecosystem":"SUSE:Package Hub 15 SP5","name":"cobbler","purl":"pkg:rpm/suse/cobbler&distro=SUSE%20Package%20Hub%2015%20SP5"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"3.3.7-bp155.2.3.2"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"cobbler":"3.3.7-bp155.2.3.2","cobbler-tests":"3.3.7-bp155.2.3.2","cobbler-tests-containers":"3.3.7-bp155.2.3.2"}]},"package":{"ecosystem":"openSUSE:Leap 15.5","name":"cobbler","purl":"pkg:rpm/opensuse/cobbler&distro=openSUSE%20Leap%2015.5"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"3.3.7-bp155.2.3.2"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for cobbler fixes the following issues:\n\nUpdate to 3.3.7:\n\n  * Security: Fix issue that allowed anyone to connect to the API\n    as admin (CVE-2024-47533, boo#1231332)\n\n  * bind - Fix bug that prevents cname entries from being\n    generated successfully\n  * Fix build on RHEL9 based distributions (fence-agents-all split)\n  * Fix for Windows systems\n  * Docs: Add missing dependencies for source installation\n  * Fix issue that prevented systems from being synced when the\n    profile was edited\n\nUpdate to 3.3.6:\n\n  * Upstream all openSUSE specific patches that were maintained in Git\n  * Fix rename of items that had uppercase letters\n  * Skip inconsistent collections instead of crashing the daemon\n\n- Update to 3.3.5:\n  * Added collection indicies for UUID's, MAC's, IP addresses and hostnames\n    boo#1219933\n  * Re-added to_dict() caching\n  * Added lazy loading for the daemon (off by default)\n\n- Update to 3.3.4:\n\n  * Added cobbler-tests-containers subpackage\n  * Updated the distro_signatures.json database\n  * The default name for grub2-efi changed to grubx64.efi to match\n    the DHCP template\n\n- Do generate boot menus even if no profiles or systems - only local boot\n- Avoid crashing running buildiso in certain conditions.\n- Fix settings migration schema to work while upgrading on existing running\n  Uyuni and SUSE Manager servers running with old Cobbler settings (boo#1203478)\n- Consider case of 'next_server' being a hostname during migration\n  of Cobbler collections.\n- Fix problem with 'proxy_url_ext' setting being None type.\n- Update v2 to v3 migration script to allow migration of collections\n  that contains settings from Cobbler 2. (boo#1203478)\n- Fix problem for the migration of 'autoinstall' collection attribute.\n- Fix failing Cobbler tests after upgrading to 3.3.3.\n- Fix regression: allow empty string as interface_type value (boo#1203478) \n- Avoid possible override of existing values during migration\n  of collections to 3.0.0 (boo#1206160)\n- Add missing code for previous patch file around boot_loaders migration.\n- Improve Cobbler performance with item cache and threadpool (boo#1205489)\n- Skip collections that are inconsistent instead of crashing (boo#1205749)\n- Items: Fix creation of 'default' NetworkInterface (boo#1206520)\n- S390X systems require their kernel options to have a linebreak at\n  79 characters (boo#1207595)\n- settings-migration-v1-to-v2.sh will now handle paths with whitespace\n  correct\n- Fix renaming Cobbler items (boo#1204900, boo#1209149)\n- Fix cobbler buildiso so that the artifact can be booted by EFI firmware.\n  (boo#1206060)\n- Add input_string_*, input_boolean, input_int functiont to public API\n","id":"openSUSE-SU-2024:0382-1","modified":"2024-11-28T17:32:46Z","published":"2024-11-28T17:32:46Z","references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CGWWFM26ZMG5SCPMDNQQNYHHTROXVX2Q/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1203478"},{"type":"REPORT","url":"https://bugzilla.suse.com/1204900"},{"type":"REPORT","url":"https://bugzilla.suse.com/1205489"},{"type":"REPORT","url":"https://bugzilla.suse.com/1205749"},{"type":"REPORT","url":"https://bugzilla.suse.com/1206060"},{"type":"REPORT","url":"https://bugzilla.suse.com/1206160"},{"type":"REPORT","url":"https://bugzilla.suse.com/1206520"},{"type":"REPORT","url":"https://bugzilla.suse.com/1207595"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209149"},{"type":"REPORT","url":"https://bugzilla.suse.com/1219933"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231332"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-47533"}],"related":["CVE-2024-47533"],"summary":"Security update for cobbler","upstream":["CVE-2024-47533"]}