Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update for grafana, kafka, logstash, openstack-monasca-installer fixes the following issues: Security issues fixed: - CVE-2018-12099: grafana: Fix XSS vulnerabilities in dashboard links (bsc#1096985). - CVE-2018-3817: logstash: Fix inadvertently logging of sensitive information (bsc#1090849). Bug fixes: - bsc#1095603: Disable jmxremote debugging. - bsc#1097847: Make time series database schema setup conditional. - bsc#1094448: Set log rotation options. - bsc#1090336: Add complete set of elasticsearch performance tunables. - bsc#1101366: Fix build issues with s390x, ppc64le and aarch64. - Fix various spec errors affecting Leap 15 and Tumbleweed Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
#1090336 #1090849 #1094448 #1095603 #1096985
#1097847 #1101366
Cross- CVE-2018-12099 CVE-2018-3817
Affected Products:
SUSE OpenStack Cloud Crowbar 8
SUSE OpenStack Cloud 8
HPE Helion Openstack 8
https://www.suse.com/security/cve/CVE-2018-12099.html
https://www.suse.com/security/cve/CVE-2018-3817.html
https://bugzilla.suse.com/1090336
https://bugzilla.suse.com/1090849
https://bugzilla.suse.com/1094448
https://bugzilla.suse.com/1095603
https://bugzilla.suse.com/1096985
https://bugzilla.suse.com/1097847
https://bugzilla.suse.com/1101366
Get the latest Linux and open source security news straight to your inbox.