<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Recommended update 4.3.15 for Multi-Linux Manager Client Tools</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-RU-2025:0791-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2025-03-06T05:28:17Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2025-03-06T05:28:17Z</InitialReleaseDate>
    <CurrentReleaseDate>2025-03-06T05:28:17Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Recommended update 4.3.15 for Multi-Linux Manager Client Tools</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update fixes the following issues:

ansible:

- Security issues fixed:
  * CVE-2024-8775: Fixed issue where sensitive information stored in Ansible Vault files
    could be exposed in plaintext (bsc#1230601)

spacewalk-client-tools:

- Version 4.3.22-0
  * Allow translation to wrap strings as weblate forces it
  * Show Source String change for translations

uyuni-proxy-systemd-services:

- Version 4.3.15-0
  * Update to Multi-Linux Manager 4.3.15

</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">SUSE-2025-791,SUSE-SLE-Manager-Tools-15-2025-791,SUSE-SLE-Manager-Tools-For-Micro-5-2025-791,SUSE-SLE-Module-SUSE-Manager-Proxy-4.3-2025-791,openSUSE-SLE-15.6-2025-791</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/-2025-791/suse-ru-20250791-1/</URL>
      <Description>Link for SUSE-RU-2025:0791-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-updates/2025-March/038632.html</URL>
      <Description>E-Mail link for SUSE-RU-2025:0791-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1230601</URL>
      <Description>SUSE Bug 1230601</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-8775/</URL>
      <Description>SUSE CVE CVE-2024-8775 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Manager Client Tools 15">
      <Branch Type="Product Name" Name="SUSE Manager Client Tools 15">
        <FullProductName ProductID="SUSE Manager Client Tools 15">SUSE Manager Client Tools 15</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Manager Client Tools for SLE Micro 5">
      <Branch Type="Product Name" Name="SUSE Manager Client Tools for SLE Micro 5">
        <FullProductName ProductID="SUSE Manager Client Tools for SLE Micro 5" CPE="cpe:/o:suse:sle-manager-tools-micro:5">SUSE Manager Client Tools for SLE Micro 5</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Manager Proxy Module 4.3">
      <Branch Type="Product Name" Name="SUSE Manager Proxy Module 4.3">
        <FullProductName ProductID="SUSE Manager Proxy Module 4.3" CPE="cpe:/o:suse:sle-module-suse-manager-proxy:4.3">SUSE Manager Proxy Module 4.3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="openSUSE Leap 15.6">
      <Branch Type="Product Name" Name="openSUSE Leap 15.6">
        <FullProductName ProductID="openSUSE Leap 15.6" CPE="cpe:/o:opensuse:leap:15.6">openSUSE Leap 15.6</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="ansible-2.9.27-150000.1.20.1">
      <FullProductName ProductID="ansible-2.9.27-150000.1.20.1">ansible-2.9.27-150000.1.20.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ansible-doc-2.9.27-150000.1.20.1">
      <FullProductName ProductID="ansible-doc-2.9.27-150000.1.20.1">ansible-doc-2.9.27-150000.1.20.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ansible-test-2.9.27-150000.1.20.1">
      <FullProductName ProductID="ansible-test-2.9.27-150000.1.20.1">ansible-test-2.9.27-150000.1.20.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-spacewalk-check-4.3.22-150000.3.100.1">
      <FullProductName ProductID="python3-spacewalk-check-4.3.22-150000.3.100.1">python3-spacewalk-check-4.3.22-150000.3.100.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-spacewalk-client-setup-4.3.22-150000.3.100.1">
      <FullProductName ProductID="python3-spacewalk-client-setup-4.3.22-150000.3.100.1">python3-spacewalk-client-setup-4.3.22-150000.3.100.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-spacewalk-client-tools-4.3.22-150000.3.100.1">
      <FullProductName ProductID="python3-spacewalk-client-tools-4.3.22-150000.3.100.1">python3-spacewalk-client-tools-4.3.22-150000.3.100.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-check-4.3.22-150000.3.100.1">
      <FullProductName ProductID="spacewalk-check-4.3.22-150000.3.100.1">spacewalk-check-4.3.22-150000.3.100.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-client-setup-4.3.22-150000.3.100.1">
      <FullProductName ProductID="spacewalk-client-setup-4.3.22-150000.3.100.1">spacewalk-client-setup-4.3.22-150000.3.100.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-client-tools-4.3.22-150000.3.100.1">
      <FullProductName ProductID="spacewalk-client-tools-4.3.22-150000.3.100.1">spacewalk-client-tools-4.3.22-150000.3.100.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="uyuni-proxy-systemd-services-4.3.15-150000.1.30.1">
      <FullProductName ProductID="uyuni-proxy-systemd-services-4.3.15-150000.1.30.1">uyuni-proxy-systemd-services-4.3.15-150000.1.30.1</FullProductName>
    </Branch>
    <Relationship ProductReference="ansible-2.9.27-150000.1.20.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Client Tools 15">
      <FullProductName ProductID="SUSE Manager Client Tools 15:ansible-2.9.27-150000.1.20.1">ansible-2.9.27-150000.1.20.1 as a component of SUSE Manager Client Tools 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="ansible-doc-2.9.27-150000.1.20.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Client Tools 15">
      <FullProductName ProductID="SUSE Manager Client Tools 15:ansible-doc-2.9.27-150000.1.20.1">ansible-doc-2.9.27-150000.1.20.1 as a component of SUSE Manager Client Tools 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-spacewalk-check-4.3.22-150000.3.100.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Client Tools 15">
      <FullProductName ProductID="SUSE Manager Client Tools 15:python3-spacewalk-check-4.3.22-150000.3.100.1">python3-spacewalk-check-4.3.22-150000.3.100.1 as a component of SUSE Manager Client Tools 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-spacewalk-client-setup-4.3.22-150000.3.100.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Client Tools 15">
      <FullProductName ProductID="SUSE Manager Client Tools 15:python3-spacewalk-client-setup-4.3.22-150000.3.100.1">python3-spacewalk-client-setup-4.3.22-150000.3.100.1 as a component of SUSE Manager Client Tools 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-spacewalk-client-tools-4.3.22-150000.3.100.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Client Tools 15">
      <FullProductName ProductID="SUSE Manager Client Tools 15:python3-spacewalk-client-tools-4.3.22-150000.3.100.1">python3-spacewalk-client-tools-4.3.22-150000.3.100.1 as a component of SUSE Manager Client Tools 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-check-4.3.22-150000.3.100.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Client Tools 15">
      <FullProductName ProductID="SUSE Manager Client Tools 15:spacewalk-check-4.3.22-150000.3.100.1">spacewalk-check-4.3.22-150000.3.100.1 as a component of SUSE Manager Client Tools 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-client-setup-4.3.22-150000.3.100.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Client Tools 15">
      <FullProductName ProductID="SUSE Manager Client Tools 15:spacewalk-client-setup-4.3.22-150000.3.100.1">spacewalk-client-setup-4.3.22-150000.3.100.1 as a component of SUSE Manager Client Tools 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-client-tools-4.3.22-150000.3.100.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Client Tools 15">
      <FullProductName ProductID="SUSE Manager Client Tools 15:spacewalk-client-tools-4.3.22-150000.3.100.1">spacewalk-client-tools-4.3.22-150000.3.100.1 as a component of SUSE Manager Client Tools 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="uyuni-proxy-systemd-services-4.3.15-150000.1.30.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Client Tools 15">
      <FullProductName ProductID="SUSE Manager Client Tools 15:uyuni-proxy-systemd-services-4.3.15-150000.1.30.1">uyuni-proxy-systemd-services-4.3.15-150000.1.30.1 as a component of SUSE Manager Client Tools 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="uyuni-proxy-systemd-services-4.3.15-150000.1.30.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Client Tools for SLE Micro 5">
      <FullProductName ProductID="SUSE Manager Client Tools for SLE Micro 5:uyuni-proxy-systemd-services-4.3.15-150000.1.30.1">uyuni-proxy-systemd-services-4.3.15-150000.1.30.1 as a component of SUSE Manager Client Tools for SLE Micro 5</FullProductName>
    </Relationship>
    <Relationship ProductReference="ansible-2.9.27-150000.1.20.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Proxy Module 4.3">
      <FullProductName ProductID="SUSE Manager Proxy Module 4.3:ansible-2.9.27-150000.1.20.1">ansible-2.9.27-150000.1.20.1 as a component of SUSE Manager Proxy Module 4.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="ansible-doc-2.9.27-150000.1.20.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Proxy Module 4.3">
      <FullProductName ProductID="SUSE Manager Proxy Module 4.3:ansible-doc-2.9.27-150000.1.20.1">ansible-doc-2.9.27-150000.1.20.1 as a component of SUSE Manager Proxy Module 4.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="uyuni-proxy-systemd-services-4.3.15-150000.1.30.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Proxy Module 4.3">
      <FullProductName ProductID="SUSE Manager Proxy Module 4.3:uyuni-proxy-systemd-services-4.3.15-150000.1.30.1">uyuni-proxy-systemd-services-4.3.15-150000.1.30.1 as a component of SUSE Manager Proxy Module 4.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="ansible-2.9.27-150000.1.20.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:ansible-2.9.27-150000.1.20.1">ansible-2.9.27-150000.1.20.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="ansible-doc-2.9.27-150000.1.20.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:ansible-doc-2.9.27-150000.1.20.1">ansible-doc-2.9.27-150000.1.20.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="ansible-test-2.9.27-150000.1.20.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:ansible-test-2.9.27-150000.1.20.1">ansible-test-2.9.27-150000.1.20.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without setting the no_log: true parameter, resulting in sensitive data being printed in the playbook output or logs. This can lead to the unintentional disclosure of secrets like passwords or API keys, compromising security and potentially allowing unauthorized access or actions.</Note>
    </Notes>
    <CVE>CVE-2024-8775</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Manager Client Tools 15:ansible-2.9.27-150000.1.20.1</ProductID>
        <ProductID>SUSE Manager Client Tools 15:ansible-doc-2.9.27-150000.1.20.1</ProductID>
        <ProductID>SUSE Manager Client Tools 15:python3-spacewalk-check-4.3.22-150000.3.100.1</ProductID>
        <ProductID>SUSE Manager Client Tools 15:python3-spacewalk-client-setup-4.3.22-150000.3.100.1</ProductID>
        <ProductID>SUSE Manager Client Tools 15:python3-spacewalk-client-tools-4.3.22-150000.3.100.1</ProductID>
        <ProductID>SUSE Manager Client Tools 15:spacewalk-check-4.3.22-150000.3.100.1</ProductID>
        <ProductID>SUSE Manager Client Tools 15:spacewalk-client-setup-4.3.22-150000.3.100.1</ProductID>
        <ProductID>SUSE Manager Client Tools 15:spacewalk-client-tools-4.3.22-150000.3.100.1</ProductID>
        <ProductID>SUSE Manager Client Tools 15:uyuni-proxy-systemd-services-4.3.15-150000.1.30.1</ProductID>
        <ProductID>SUSE Manager Client Tools for SLE Micro 5:uyuni-proxy-systemd-services-4.3.15-150000.1.30.1</ProductID>
        <ProductID>SUSE Manager Proxy Module 4.3:ansible-2.9.27-150000.1.20.1</ProductID>
        <ProductID>SUSE Manager Proxy Module 4.3:ansible-doc-2.9.27-150000.1.20.1</ProductID>
        <ProductID>SUSE Manager Proxy Module 4.3:uyuni-proxy-systemd-services-4.3.15-150000.1.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:ansible-2.9.27-150000.1.20.1</ProductID>
        <ProductID>openSUSE Leap 15.6:ansible-doc-2.9.27-150000.1.20.1</ProductID>
        <ProductID>openSUSE Leap 15.6:ansible-test-2.9.27-150000.1.20.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/-2025-791/suse-ru-20250791-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-8775.html</URL>
        <Description>CVE-2024-8775</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1230601</URL>
        <Description>SUSE Bug 1230601</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
