SUSE SLES15:golang-github-prometheus-alertmanager/etc(SUSE-SU-2026:3714-1)

high Nessus プラグイン ID 339763

Language:

概要

リモートの SUSE ホストに 1 つ以上のセキュリティ更新がありません。

説明

リモートの SUSE Linux SLES15 ホストには、SUSE-SU-2026:3714-1 のアドバイザリに記載された複数の脆弱性の影響を受けるパッケージがインストールされています。

prometheus-postgres_exporter:

- CVE-2022-21698:github.com/prometheus/client_golang をバージョン 1.11.1 で置き換え、検証のバイパスと権限昇格を回避します(bsc#1248699)

golang-github-prometheus-alertmanager:

- CVE-2026-39821:golang.org/x/net をバージョン 0.55.0 に更新することで、検証のバイパスと権限昇格を修正します(bsc#1266615)

golang-github-prometheus-prometheus はバージョン 3.5.3 から 3.5.4 に更新されました:

セキュリティ修正:

- CVE-2026-39882:OpenTelemetry を 1.43.0 に更新することにより、際限のない HTTP 応答本文の読み取りを修正します(bsc#1274221)
- CVE-2026-33244:react-router の HTTP Location ヘッダー値の不適切な中和を修正しました(bsc#1267416)
- CVE-2026-13149:ブレース拡張をバージョン 5.0.7 に更新することで、起こり得る DoS を防止します(bsc#1269917)
- CVE-2026-33814:HTTP/2 トランスポートの無限ループを修正しました(bsc#1265827)


Tenable は、前述の記述ブロックを SUSE セキュリティアドバイザリから直接抽出しています。

Nessus はこれらの問題をテストしておらず、代わりにアプリケーションが自己報告するバージョン番号にのみ依存していることに注意してください。

ソリューション

影響を受けるgolang-github-prometheus-alertmanagerやgolang-github-prometheus-prometheusパッケージを更新してください。

参考資料

https://bugzilla.suse.com/1248699

https://bugzilla.suse.com/1262187

https://bugzilla.suse.com/1263272

https://bugzilla.suse.com/1265827

https://bugzilla.suse.com/1266615

https://bugzilla.suse.com/1267416

https://bugzilla.suse.com/1269917

https://bugzilla.suse.com/1271327

https://bugzilla.suse.com/1271331

https://bugzilla.suse.com/1274217

https://bugzilla.suse.com/1274221

https://lists.suse.com/pipermail/sle-updates/2026-August/049453.html

https://www.suse.com/security/cve/CVE-2022-21698

https://www.suse.com/security/cve/CVE-2025-12141

https://www.suse.com/security/cve/CVE-2026-13149

https://www.suse.com/security/cve/CVE-2026-33244

https://www.suse.com/security/cve/CVE-2026-33382

https://www.suse.com/security/cve/CVE-2026-33814

https://www.suse.com/security/cve/CVE-2026-39821

https://www.suse.com/security/cve/CVE-2026-39882

https://www.suse.com/security/cve/CVE-2026-41607

プラグインの詳細

深刻度: High

ID: 339763

ファイル名: suse_SU-2026-3714-1.nasl

バージョン: 1.2

タイプ: Local

エージェント: unix

公開日: 2026/8/26

更新日: 2026/8/27

サポートされているセンサー: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

リスク情報

VPR

リスクファクター: Medium

スコア: 4.8

パーセンタイル: 57.83

CVSS v2

リスクファクター: Medium

基本値: 5

現状値: 3.7

ベクトル: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS スコアのソース: CVE-2022-21698

CVSS v3

リスクファクター: Medium

基本値: 6.5

現状値: 5.7

ベクトル: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

現状ベクトル: CVSS:3.0/E:U/RL:O/RC:C

CVSS スコアのソース: CVE-2025-12141

CVSS v4

リスクファクター: High

Base Score: 8.7

Threat Score: 7.7

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CVSS スコアのソース: CVE-2026-13149

脆弱性情報

CPE: cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:golang-github-prometheus-alertmanager, p-cpe:/a:novell:suse_linux:golang-github-prometheus-prometheus

必要な KB アイテム: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

エクスプロイトの容易さ: No known exploits are available

パッチ公開日: 2026/8/24

脆弱性公開日: 2022/2/15

参照情報

CVE: CVE-2022-21698, CVE-2025-12141, CVE-2026-13149, CVE-2026-33244, CVE-2026-33382, CVE-2026-33814, CVE-2026-39821, CVE-2026-39882, CVE-2026-41607

SuSE: SUSE-SU-2026:3714-1