RedHat: RHSA-2019-0567:01 Moderate: openstack-octavia security and bug fix
Summary
The OpenStack Load Balancing service (openstack-octavia) provides a Load
Balancing-as-a-Service (LBaaS) version 2 implementation for Red Hat
OpenStack platform director based installations.
Security Fix(es):
* openstack-octavia: Private keys written to world-readable log files
(CVE-2018-16856)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Bug Fix(es):
* This feature is "community support" and not supported by Red Hat per
RHOSP SLA. (BZ#1671022)
Summary
Solution
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
References
https://access.redhat.com/security/cve/CVE-2018-16856 https://access.redhat.com/security/updates/classification/#moderate
Package List
Red Hat OpenStack Platform 13.0:
Source:
openstack-octavia-2.0.3-2.el7ost.src.rpm
noarch:
openstack-octavia-amphora-agent-2.0.3-2.el7ost.noarch.rpm
openstack-octavia-api-2.0.3-2.el7ost.noarch.rpm
openstack-octavia-common-2.0.3-2.el7ost.noarch.rpm
openstack-octavia-diskimage-create-2.0.3-2.el7ost.noarch.rpm
openstack-octavia-health-manager-2.0.3-2.el7ost.noarch.rpm
openstack-octavia-housekeeping-2.0.3-2.el7ost.noarch.rpm
openstack-octavia-worker-2.0.3-2.el7ost.noarch.rpm
python-octavia-2.0.3-2.el7ost.noarch.rpm
ppc64le:
openstack-octavia-debuginfo-2.0.3-2.el7ost.ppc64le.rpm
python-octavia-tests-golang-2.0.3-2.el7ost.ppc64le.rpm
x86_64:
openstack-octavia-debuginfo-2.0.3-2.el7ost.x86_64.rpm
python-octavia-tests-golang-2.0.3-2.el7ost.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
Topic
An update for openstack-octavia is now available for Red Hat OpenStackPlatform 13.0 (Queens).Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.
Topic
Relevant Releases Architectures
Red Hat OpenStack Platform 13.0 - noarch, ppc64le, x86_64
Bugs Fixed
1547478 - Test Octavia with OVN
1571636 - Backports of general improvements to Octavia
1582145 - Listener's "operating status" is not transitioning to ONLINE even when pool and members are configured for it.
1607276 - All existing amphora instances are deleting when RabbitMQ is down
1649165 - CVE-2018-16856 openstack-octavia: Private keys written to world-readable log files
1669078 - Add support for configuring Octavia LB timeouts in OSP 13
1670170 - Rebase openstack-octavia to 2.0.3
1672370 - flake8 fail: code over-indentation