SUSE: 2020:0081-1 moderate: crowbar-core, crowbar-openstack, openstack-horizon-plugin-monasca-ui, openstack-monasca-api, openstack-monasca-log-api, openstack-neutron, rubygem-puma, rubygem-rest-client
Summary
This update for crowbar-core, crowbar-openstack, openstack-horizon-plugin-monasca-ui, openstack-monasca-api, openstack-monasca-log-api, openstack-neutron, rubygem-puma, rubygem-rest-client contains the following fixes: Security issue fixed for rubygem-puma: - CVE-2019-16770: Fixed a potential denial of service in Puma's reactor (bsc#1158675, jsc#SOC-10999) Security issue fixed for rubygem-rest-client: - CVE-2015-3448: Fixed a plain text local password disclosure. (bsc#917802) Updates for crowbar-core: - Update to version 4.0+git.1574788924.e4a6aeb0c: * Allow pacemaker remotes for upgrade (SOC-10133) - Update to version 4.0+git.1574713660.972029d1a: * Ignore CVE-2019-13117 in CI builds (bsc#1157028) Updates for crowbar-openstack: - Update to version 4.0+git.1574869671.9c7bade2d: * tempest: configure Kibana version (SOC-10131) - Update to version 4.0+git.1574764112.c260c70e5: * horizon: install lbaas horizon...
Read the Full AdvisoryReferences
#1157028 #1157482 #1158675 #917802
Cross- CVE-2015-3448 CVE-2019-13117 CVE-2019-16770
Affected Products:
SUSE OpenStack Cloud 7
https://www.suse.com/security/cve/CVE-2015-3448.html
https://www.suse.com/security/cve/CVE-2019-13117.html
https://www.suse.com/security/cve/CVE-2019-16770.html
https://bugzilla.suse.com/1157028
https://bugzilla.suse.com/1157482
https://bugzilla.suse.com/1158675
https://bugzilla.suse.com/917802