Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

SUSE: 2018:2576-1 Moderate: OpenStack Authentication Fix

suse
Calendar Grey August 31, 2018
Dist Suse Esm H88
SUSE has released a security update for OpenStack, which resolves a significant vulnerability and implements various improvements to bolster both security and efficiency.
An update that solves one vulnerability and has four fixes is now available

Summary

This update for OpenStack fixes the following issues: The following security issue with openstack-keystone has been fixed: - CVE-2018-14432: Reduce duplication in federated authentication APIs. (bsc#1102151) Additionally, the following non-security issues have been fixed: openstack-dashboard: - Fetch and show Cinder availability zones list during volume creation and volume creation from image. (bsc#1100751) openstack-heat: - Add Trunk resource support. openstack-horizon-plugin-designate-ui: - Install all designate panels that are available. openstack-nova: - Stop _undefine_domain erroring if domain not found. (bsc#1099902) - Fix Nova to allow using cinder v3 endpoint. (bsc#1095482) python-os-vif: - Check if interface belongs to a Linux Bridge before removing. (bsc#1084724)

References

#1084724 #1095482 #1099902 #1100751 #1102151

Cross- CVE-2018-14432

Affected Products:

SUSE OpenStack Cloud 7

https://www.suse.com/security/cve/CVE-2018-14432.html

https://bugzilla.suse.com/1084724

https://bugzilla.suse.com/1095482

https://bugzilla.suse.com/1099902

https://bugzilla.suse.com/1100751

https://bugzilla.suse.com/1102151

Announcement ID: SUSE-SU-2018:2576-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here