SUSE has issued an advisory today (June 14): http://lists.suse.com/pipermail/sle-security-updates/2018-June/004191.html It was fixed in 3.24. We won't be fixing this issue.
Bug filed just to document it.
Status: NEW => RESOLVEDResolution: (none) => OLD