[SUSE-SU-2024:1838-1] Security update for warewulf4

Severity Important
CVEs 1

Security update for warewulf4

This update for warewulf4 fixes the following issues:

  • fixed wwctl configure --all doesn't configure ssh (bsc#1225402)

  • update to 4.5.2 with following changes:

    • Reorder dnsmasq config to put iPXE last
    • Update go-digest dependency to fix CVE-2024-3727: digest values not always validated (bsc#1224124)
  • updated to version 4.5.1 with following changes

    • wwctl [profile|node] list -a handles now slices correclty
    • Fix a locking issue with concurrent read/writes for node status
  • Remove API package as use of this wasn't documented

  • use tftp.socket for activation (bsc#1216994)

# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date