Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE OpenStack 8: 2018:3563-1 Important: Kafka Data Loss Alert

suse
Calendar Grey October 30, 2018
Dist Suse Esm H88
Important release for SUSE targeting Kafka data integrity issues along with essential improvements in multiple software components.
An update that solves one vulnerability and has three fixes is now available

Summary

This update for ardana-monasca, ardana-spark, kafka, kafka-kit, openstack-monasca-api fixes the following issues: This update for ardana-monasca to version 8.0+git.1535031421.9262a47 fixes these issues: - Requests Apache to reload on change (bsc#1102662) - Avoids managing non-Monasca users (bsc#1102662) - Line up perms on storm.conf to match rpm (bsc#1094971) This update for ardana-spark to version 8.0+git.1532114050.04654a8 fixes this issue: - Only set log dir perms on legacy install (bsc#1094851) This update for kafka to version 0.10.2.2 fixes this security issue: - CVE-2018-1288: Authenticated Kafka users may have performed action reserved for the Broker via a manually created fetch request interfering with data replication, resulting in data loss (bsc#1102920).

References

#1094851 #1094971 #1102662 #1102920

Cross- CVE-2018-1288

Affected Products:

SUSE OpenStack Cloud Crowbar 8

SUSE OpenStack Cloud 8

HPE Helion Openstack 8

https://www.suse.com/security/cve/CVE-2018-1288.html

https://bugzilla.suse.com/1094851

https://bugzilla.suse.com/1094971

https://bugzilla.suse.com/1102662

https://bugzilla.suse.com/1102920

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:3563-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here