SUSE: 2020:1748-1 important: ceph
Summary
This is a version update for ceph to version 12.2.13: Security issue fixed: - CVE-2020-10753: Fixed an HTTP header injection via CORS ExposeHeader tag (bsc#1171921). - Notable changes in this update for ceph: * mgr: telemetry: backported and now available on SES5.5. Please consider enabling via "ceph telemetry on" (bsc#1171670) * OSD heartbeat ping time: new health warning, options and admin commands (bsc#1171960) * "osd_calc_pg_upmaps_max_stddev" ceph.conf parameter has been removed; use "upmap_max_deviation" instead (bsc#1171961) * Default maximum concurrent bluestore rocksdb compaction threads raised from 1 to 2 for improved ability to keep up with rgw bucket index workloads (bsc#1171963) - Bug fixes in this ceph update: * mon: Error message displayed when mon_osd_max_split_count would be exceeded is not as user-friendly as it could be (bsc#1126230) * ceph_volume_client: remove ceph ...
Read the Full AdvisoryReferences
#1126230 #1136082 #1157607 #1161096 #1162553
#1171670 #1171921 #1171960 #1171961 #1171963
Cross- CVE-2020-10753
Affected Products:
SUSE OpenStack Cloud Crowbar 8
SUSE OpenStack Cloud 8
SUSE Linux Enterprise Software Development Kit 12-SP5
SUSE Linux Enterprise Software Development Kit 12-SP4
SUSE Linux Enterprise Server for SAP 12-SP3
SUSE Linux Enterprise Server 12-SP5
SUSE Linux Enterprise Server 12-SP4
SUSE Linux Enterprise Server 12-SP3-LTSS
SUSE Linux Enterprise Server 12-SP3-BCL
SUSE Enterprise Storage 5
HPE Helion Openstack 8
https://www.suse.com/security/cve/CVE-2020-10753.html
https://bugzilla.suse.com/1126230
https://bugzilla.suse.com/1136082
https://bugzilla.suse.com/1157607
https://bugzilla.suse.com/1161096
...
Read the Full Advisory