Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora: Update python-keystonemiddleware 1.3.2 Critical: S3Token Issue

fedora
Calendar Grey July 19, 2015
Dist Fedora Esm H88
Update to python-keystonemiddleware 1.3.2 addresses CVE-2015-1852 with S3Token fixes for Fedora 22.
Update to upstream 1.3.2 which incldes fix for CVE-2015-1852 Update to upstream 1.3.1 + S3token incorrect condition expression for ssl_insecure CVE-2015-1852

Summary

This package contains middleware modules designed to provide authentication

and authorization features to web services other than OpenStack Keystone.

The most prominent module is keystonemiddleware.auth_token.

This package does not expose any CLI or Python API features.

Update Information:

Update to upstream 1.3.2 which incldes fix for CVE-2015-1852 Update to upstream 1.3.1 + S3token incorrect condition expression for ssl_insecure CVE-2015-1852

Change Log

* Tue Jul 14 2015 Alan Pevec 1.3.2-1 - Update to upstream 1.3.2 * Fri May 1 2015 Alan Pevec 1.3.1-1 - Update to upstream 1.3.1 - S3token incorrect condition expression for ssl_insecure CVE-2015-1852

References


[ 1 ] Bug #1209527 - CVE-2015-1852 OpenStack keystonemiddleware/keystoneclient: S3Token TLS cert verification option not honored https://bugzilla.redhat.com/show_bug.cgi?id=1209527

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update python-keystonemiddleware' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: python-keystonemiddleware
Product: Fedora 22
Version: 1.3.2
Release: 1.fc22
Summary: Middleware for OpenStack Identity

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here