Alerts This Week
Warning Icon 1 924
Alerts This Week
Warning Icon 1 924

SUSE: 2020:0081-1 Moderate: OpenStack Security Update for Denial of Service

suse
Calendar Grey January 13, 2020
Dist Suse Esm H88
SUSE Security Patch for Various OpenStack Elements Tackling Moderate Vulnerabilities with Security Resolutions.
An update that solves three vulnerabilities and has one errata is now available

Summary

This update for crowbar-core, crowbar-openstack, openstack-horizon-plugin-monasca-ui, openstack-monasca-api, openstack-monasca-log-api, openstack-neutron, rubygem-puma, rubygem-rest-client contains the following fixes: Security issue fixed for rubygem-puma: - CVE-2019-16770: Fixed a potential denial of service in Puma's reactor (bsc#1158675, jsc#SOC-10999) Security issue fixed for rubygem-rest-client: - CVE-2015-3448: Fixed a plain text local password disclosure. (bsc#917802) Updates for crowbar-core: - Update to version 4.0+git.1574788924.e4a6aeb0c: * Allow pacemaker remotes for upgrade (SOC-10133) - Update to version 4.0+git.1574713660.972029d1a: * Ignore CVE-2019-13117 in CI builds (bsc#1157028) Updates for crowbar-openstack:

References

#1157028 #1157482 #1158675 #917802

Cross- CVE-2015-3448 CVE-2019-13117 CVE-2019-16770

Affected Products:

SUSE OpenStack Cloud 7

https://www.suse.com/security/cve/CVE-2015-3448.html

https://www.suse.com/security/cve/CVE-2019-13117.html

https://www.suse.com/security/cve/CVE-2019-16770.html

https://bugzilla.suse.com/1157028

https://bugzilla.suse.com/1157482

https://bugzilla.suse.com/1158675

https://bugzilla.suse.com/917802

Announcement ID: SUSE-SU-2020:0081-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here