This update for ardana-ansible, ardana-cinder, ardana-cobbler, ardana-installer-ui, ardana-opsconsole-ui, ardana-osconfig, crowbar-core, grafana, grafana-natel-discrete-panel, openstack-cinder, openstack-dashboard, openstack-ironic, openstack-ironic-python-agent, openstack-manila, openstack-neutron, openstack-neutron-infoblox, openstack-nova, python-Flask-Cors, rubygem-crowbar-client, storm, storm-kit, venv-openstack-cinder, venv-openstack-horizon fixes the following issues: Security changes on this update: grafana: - CVE-2018-18623, CVE-2018-18624, CVE-2018-18625: Fixed multiple XSS vulnerabilities, caused by an incomplete fix for CVE-2018-12099 (bsc#1172450). - CVE-2020-11110: Fixed a stored XSS in dashboard snapshots (bsc#1174583). openstack-nova:
#1117080 #1142617 #1143163 #1172450 #1174583
#1175484 #1175986 SOC-10300 SOC-10522 SOC-11184
SOC-11223 SOC-11364 SOC-5480 SOC-9008 SOC-9779
SOC-9974 SOC-9998
Cross- CVE-2018-11779 CVE-2018-17954 CVE-2018-18623
CVE-2018-18624 CVE-2018-18625 CVE-2019-0202
CVE-2020-11110 CVE-2020-17376 CVE-2020-25032
Affected Products:
SUSE OpenStack Cloud Crowbar 9
SUSE OpenStack Cloud 9
https://www.suse.com/security/cve/CVE-2018-11779.html
https://www.suse.com/security/cve/CVE-2018-17954.html
https://www.suse.com/security/cve/CVE-2018-18623.html
https://www.suse.com/security/cve/CVE-2018-18624.html
https://www.suse.com/security/cve/CVE-2018-18625.html
https://www.suse.com/security/cve/CVE-2019-0202.html
Get the latest Linux and open source security news straight to your inbox.