openSUSE 16: glab / glab-bash-completion / glab-fish-completion / etc (openSUSE-SU-2026:21662-1)

high Nessus Plugin ID 341170

Synopsis

The remote openSUSE host is missing one or more security updates.

Description

The remote openSUSE 16 host has packages installed that are affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:21662-1 advisory.

Changes in glab:

- Update to version 1.114.0:
* feat(api): support dynamic custom headers for authenticating proxies
* feat(artifact-registry): add glab artifact-registry login --docker
* feat(artifact-registry): resolve artifact registries in the Docker credential helper
* feat(mr): show source and target branches in view
* feat(update): detect more install methods for the upgrade nudge
* fix(cmdutils): resolve same-host SSH remotes to the right account
* fix(config): resolve YAML alias nodes in hosts config
* fix(git): detect no git repository by exit status, not message text
* fix: glab can not set group level variable masked or masked and hidden

- CVE-2026-39821: reject all-ASCII xn-- Punycode labels in the vendored golang.org/x/net/idna package regardless of Go's unicode.Version (boo#1266614).

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected glab, glab-bash-completion, glab-fish-completion and / or glab-zsh-completion packages.

See Also

https://bugzilla.suse.com/1227037

https://bugzilla.suse.com/1235353

https://bugzilla.suse.com/1241815

https://bugzilla.suse.com/1251467

https://bugzilla.suse.com/1251685

https://bugzilla.suse.com/1265775

https://bugzilla.suse.com/1265832

https://bugzilla.suse.com/1266172

https://bugzilla.suse.com/1266614

https://bugzilla.suse.com/1267155

https://www.suse.com/security/cve/CVE-2024-45338

https://www.suse.com/security/cve/CVE-2024-6104

https://www.suse.com/security/cve/CVE-2025-22872

https://www.suse.com/security/cve/CVE-2025-47911

https://www.suse.com/security/cve/CVE-2025-58190

https://www.suse.com/security/cve/CVE-2026-25681

https://www.suse.com/security/cve/CVE-2026-27136

https://www.suse.com/security/cve/CVE-2026-33814

https://www.suse.com/security/cve/CVE-2026-39821

https://www.suse.com/security/cve/CVE-2026-39827

https://www.suse.com/security/cve/CVE-2026-39828

https://www.suse.com/security/cve/CVE-2026-39829

https://www.suse.com/security/cve/CVE-2026-39830

https://www.suse.com/security/cve/CVE-2026-39831

https://www.suse.com/security/cve/CVE-2026-39832

https://www.suse.com/security/cve/CVE-2026-39833

https://www.suse.com/security/cve/CVE-2026-39834

https://www.suse.com/security/cve/CVE-2026-39835

https://www.suse.com/security/cve/CVE-2026-42502

https://www.suse.com/security/cve/CVE-2026-42506

https://www.suse.com/security/cve/CVE-2026-42508

https://www.suse.com/security/cve/CVE-2026-46595

https://www.suse.com/security/cve/CVE-2026-46597

https://www.suse.com/security/cve/CVE-2026-46598

Plugin Details

Severity: High

ID: 341170

File Name: openSUSE-2026-21662-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/28/2026

Updated: 8/28/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.1

Percentile: 96.42

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:N/A:N

CVSS Score Source: CVE-2024-6104

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.7

Threat Score: 6.6

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2024-45338

Vulnerability Information

CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:glab-bash-completion, p-cpe:/a:novell:opensuse:glab-fish-completion, p-cpe:/a:novell:opensuse:glab-zsh-completion, p-cpe:/a:novell:opensuse:glab

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/26/2026

Vulnerability Publication Date: 6/24/2024

Reference Information

CVE: CVE-2024-45338, CVE-2024-6104, CVE-2025-22872, CVE-2025-47911, CVE-2025-58190, CVE-2026-25681, CVE-2026-27136, CVE-2026-33814, CVE-2026-39821, CVE-2026-39827, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-39835, CVE-2026-42502, CVE-2026-42506, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, CVE-2026-46598