Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Fedora 29: Security Advisory for osbs-client Critical Access Token Issue

fedora
Calendar Grey April 18, 2019
Dist Fedora Esm H88
A recent update addresses a significant vulnerability in the osbs-client that impacts users on Fedora 29, specifically concerning the unintended exposure of access tokens.
Fixes for https://bugzilla.redhat.com/show_bug.cgi?id=1697217

Summary

It is able to query OpenShift v3 for various stuff related to building images.

It can initiate builds, list builds, get info about builds, get build logs...

This package contains osbs command line client.

Fixes for https://bugzilla.redhat.com/show_bug.cgi?id=1697217

* Mon Apr 8 2019 Clement Verna - 0.52-2

- Fixes for https://bugzilla.redhat.com/show_bug.cgi?id=1697217

* Mon Dec 3 2018 Clement Verna - 0.52-1

- Update to latest upstream

[ 1 ] Bug #1697217 - osbs-client: Debug log contains URL part with oauth access_token of openshift [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1697217

su -c 'dnf upgrade --advisory FEDORA-2019-b6ec9df480' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 29
Version: 0.52
Release: 2.fc29
Summary: Python command line client for OpenShift Build Service

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here