Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

SUSE: 2020:2876-1 critical: ardana software security improvements

suse
Calendar Grey October 7, 2020
Dist Suse Esm H88
SUSE Security update: Critical revisions for ardana software addressing vulnerabilities and enhancements.
An update that fixes 9 vulnerabilities, contains 10 features is now available

Summary

This update for ardana-ansible, ardana-cinder, ardana-cobbler, ardana-installer-ui, ardana-opsconsole-ui, ardana-osconfig, crowbar-core, grafana, grafana-natel-discrete-panel, openstack-cinder, openstack-dashboard, openstack-ironic, openstack-ironic-python-agent, openstack-manila, openstack-neutron, openstack-neutron-infoblox, openstack-nova, python-Flask-Cors, rubygem-crowbar-client, storm, storm-kit, venv-openstack-cinder, venv-openstack-horizon fixes the following issues: Security changes on this update: grafana: - CVE-2018-18623, CVE-2018-18624, CVE-2018-18625: Fixed multiple XSS vulnerabilities, caused by an incomplete fix for CVE-2018-12099 (bsc#1172450). - CVE-2020-11110: Fixed a stored XSS in dashboard snapshots (bsc#1174583). openstack-nova:

References

#1117080 #1142617 #1143163 #1172450 #1174583

#1175484 #1175986 SOC-10300 SOC-10522 SOC-11184

SOC-11223 SOC-11364 SOC-5480 SOC-9008 SOC-9779

SOC-9974 SOC-9998

Cross- CVE-2018-11779 CVE-2018-17954 CVE-2018-18623

CVE-2018-18624 CVE-2018-18625 CVE-2019-0202

CVE-2020-11110 CVE-2020-17376 CVE-2020-25032

Affected Products:

SUSE OpenStack Cloud Crowbar 9

SUSE OpenStack Cloud 9

https://www.suse.com/security/cve/CVE-2018-11779.html

https://www.suse.com/security/cve/CVE-2018-17954.html

https://www.suse.com/security/cve/CVE-2018-18623.html

https://www.suse.com/security/cve/CVE-2018-18624.html

https://www.suse.com/security/cve/CVE-2018-18625.html

https://www.suse.com/security/cve/CVE-2019-0202.html

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:2876-1
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here