Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE: 2021:1962-1 Moderate: OpenStack DoS and Security Fixes

suse
Calendar Grey June 11, 2021
Scroller Suse
This release resolves 15 vulnerabilities found in multiple libraries, enhancing the overall safety of the system.
An update that fixes 23 vulnerabilities, contains two features is now available

Summary

This update for ardana-neutron, ardana-swift, cassandra, crowbar-openstack, grafana, kibana, openstack-dashboard, openstack-ironic, openstack-neutron, openstack-neutron-gbp, openstack-nova, python-Django1, python-py, python-pysaml2, python-xmlschema, rubygem-activerecord-session_store, venv-openstack-keystone contains the following fixes: Security fixes included in this update: cassandra: - CVE-2020-17516: Fixed an issue where encryption between nodes was not enforced correctly for certain internode_encryption settings (bsc#1181689) grafana: - CVE-2018-18623, CVE-2018-18624, CVE-2018-18625: Fixed multiple cross site scripting vulnerabilities in the dashboard. (bsc#1172450) - CVE-2021-27358: Fixed a denial of service via remote API call. (bsc#1183803)

References

#1044849 #1048688 #1115960 #1148383 #1170657

#1171909 #1172409 #1172450 #1174583 #1178243

#1179805 #1181277 #1181278 #1181689 #1181690

#1182317 #1182433 #1183174 #1183803 #1184148

#1185623 #1186608 #1186611 SOC-10357 SOC-11453

Cross- CVE-2017-11481 CVE-2017-11499 CVE-2018-18623

CVE-2018-18624 CVE-2018-18625 CVE-2018-19039

CVE-2019-15043 CVE-2019-25025 CVE-2020-10743

CVE-2020-11110 CVE-2020-12052 CVE-2020-13379

CVE-2020-17516 CVE-2020-24303 CVE-2020-29651

CVE-2021-21238 CVE-2021-21239 CVE-2021-23336

CVE-2021-27358 CVE-2021-28658 CVE-2021-31542

CVE-2021-33203 CVE-2021-33571

CVSS scores:

CVE-2017-11481 (NVD) : 6.1 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CVE-2017-11481 (SUSE): 5.4 CVSS:3.0/AV:N/AC:L/PR:N/U...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:1962-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.