Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

openSUSE 15.3: 2021:2664-1 Moderate: Prometheus Configuration Fix

opensuse
Calendar Grey August 12, 2021
Dist Opensuse Esm H88
Patch release for golang-github-prometheus-prometheus now ready, introducing both security fixes and various improvements for openSUSE.
An update that fixes one vulnerability, contains one feature is now available

Description

This update for golang-github-prometheus-prometheus fixes the following

issues:

- Provide and reload firewalld configuration only for:

+ openSUSE Leap 15.0, 15.1, 15.2

+ SUSE SLE15, SLE15 SP1, SLE15 SP2

- Upgrade to upstream version 2.27.1 (jsc#SLE-18254)

+ Bugfix:

* SECURITY: Fix arbitrary redirects under the /new endpoint

(CVE-2021-29622, bsc#1186242)

+ Features:

* Promtool: Retroactive rule evaluation functionality. #7675

* Configuration: Environment variable expansion for external labels.

Behind --enable-feature=expand-external-labels flag. #8649

* TSDB: Add a flag(--storage.tsdb.max-block-chunk-segment-size) to

control the max chunks file size of the blocks for small Prometheus

instances.

* UI: Add a dark theme. #8604

* AWS Lightsail Discovery: Add AWS Lightsail Discovery. #8693

* Docker Discovery: Add Docker Service Discovery. #8629

* OAuth: Allow OAuth 2.0...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.3:

zypper in -t patch openSUSE-SLE-15.3-2021-2664=1

Package List

- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):

golang-github-prometheus-prometheus-2.27.1-3.8.1

References

https://www.suse.com/security/cve/CVE-2021-29622.html

https://bugzilla.suse.com/1186242

Announcement ID: openSUSE-SU-2021:2664-1
Rating: moderate
Affected Products: openSUSE Leap 15.3 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here