Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update for crowbar-core, crowbar-openstack, grafana, influxdb, openstack-heat-templates, openstack-nova, python-Jinja2 fixes the following issues: Security fixes included in this request: grafana: - CVE-2020-24303: Fixed an XXS with series overides. (bsc#1178243) influxdb: - CVE-2019-20933: Fixed an authentication bypass. (bsc#1178988) python-Jinja2: - CVE-2019-10906, CVE-2019-8341, CVE-2016-10745: "SandboxedEnvironment" securely handles "str.format_map" in order to prevent code execution through untrusted format strings. (bsc#1132323, bsc#1125815, bsc#1132174) Non-security fixes included in this request: Changes in crowbar-core.SUSE_SLE-12-SP3_Update_Products_Cloud8: - Update to version 5.0+git.1606840757.839a64745: * ntp: Do not use rate-limiting (bsc#1179161)
#1117080 #1125815 #1132174 #1132323 #1178243
#1178988 #1179161 SOC-11240
Cross- CVE-2016-10745 CVE-2018-17954 CVE-2019-10906
CVE-2019-20933 CVE-2019-8341 CVE-2020-24303
Affected Products:
SUSE OpenStack Cloud Crowbar 8
SUSE OpenStack Cloud 8
HPE Helion Openstack 8
https://www.suse.com/security/cve/CVE-2016-10745.html
https://www.suse.com/security/cve/CVE-2018-17954.html
https://www.suse.com/security/cve/CVE-2019-10906.html
https://www.suse.com/security/cve/CVE-2019-20933.html
https://www.suse.com/security/cve/CVE-2019-8341.html
https://www.suse.com/security/cve/CVE-2020-24303.html
https://bugzilla.suse.com/1117080
https://bugzilla.suse.com/1125815
https://bugzilla.suse.com/1132174
https://bugzilla.suse.com/1132323
Get the latest Linux and open source security news straight to your inbox.