Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE: 2020:3896-1 Important: Crowbar, Grafana, InfluxDB Security

suse
Calendar Grey December 21, 2020
Scroller Suse
A significant patch addresses various problems in crowbar-core, grafana, and influxdb within the SUSE OpenStack Cloud 8 environment.
An update that solves 6 vulnerabilities, contains one feature and has one errata is now available

Summary

This update for crowbar-core, crowbar-openstack, grafana, influxdb, openstack-heat-templates, openstack-nova, python-Jinja2 fixes the following issues: Security fixes included in this request: grafana: - CVE-2020-24303: Fixed an XXS with series overides. (bsc#1178243) influxdb: - CVE-2019-20933: Fixed an authentication bypass. (bsc#1178988) python-Jinja2: - CVE-2019-10906, CVE-2019-8341, CVE-2016-10745: "SandboxedEnvironment" securely handles "str.format_map" in order to prevent code execution through untrusted format strings. (bsc#1132323, bsc#1125815, bsc#1132174) Non-security fixes included in this request: Changes in crowbar-core.SUSE_SLE-12-SP3_Update_Products_Cloud8: - Update to version 5.0+git.1606840757.839a64745: * ntp: Do not use rate-limiting (bsc#1179161)

References

#1117080 #1125815 #1132174 #1132323 #1178243

#1178988 #1179161 SOC-11240

Cross- CVE-2016-10745 CVE-2018-17954 CVE-2019-10906

CVE-2019-20933 CVE-2019-8341 CVE-2020-24303

Affected Products:

SUSE OpenStack Cloud Crowbar 8

SUSE OpenStack Cloud 8

HPE Helion Openstack 8

https://www.suse.com/security/cve/CVE-2016-10745.html

https://www.suse.com/security/cve/CVE-2018-17954.html

https://www.suse.com/security/cve/CVE-2019-10906.html

https://www.suse.com/security/cve/CVE-2019-20933.html

https://www.suse.com/security/cve/CVE-2019-8341.html

https://www.suse.com/security/cve/CVE-2020-24303.html

https://bugzilla.suse.com/1117080

https://bugzilla.suse.com/1125815

https://bugzilla.suse.com/1132174

https://bugzilla.suse.com/1132323

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:3896-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.