This update for OpenStack fixes the following issues: The following security issue with openstack-keystone has been fixed: - CVE-2018-14432: Reduce duplication in federated authentication APIs. (bsc#1102151) Additionally, the following non-security issues have been fixed: aodh: - Support same projects in different domain. barbican: - Add zuulv3 to Pike. cinder: - Empty option value maybe cause Unity driver failed to initialize. - GoodnessWeigher schedules non-type volumes. - Fix quota error when deleting temporary volume. - Fix cinder quota-usage error. - Unity: Return logged-out initiators. - Correct S-Series to DS-Series systems. - Update storage backends supported for Lenovo. - Unity: Add support of removing empty host. - NetApp: Fix to support SVM scoped permissions.
#1084362 #1102151
Cross- CVE-2018-14432
Affected Products:
SUSE OpenStack Cloud Crowbar 8
SUSE OpenStack Cloud 8
HPE Helion Openstack 8
https://www.suse.com/security/cve/CVE-2018-14432.html
https://bugzilla.suse.com/1084362
https://bugzilla.suse.com/1102151
Get the latest Linux and open source security news straight to your inbox.