Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

SUSE: 2021:3728-1 Moderate: Ardana Ansible and Monasca Update

suse
Calendar Grey November 19, 2021
Scroller Suse
Enhancements made for ardana-ansible, ardana-monasca, along with various other SUSE packages addressing XSS vulnerabilities and HTTP concerns. Discover more!
An update that fixes two vulnerabilities, contains one feature is now available

Summary

This update for ardana-ansible, ardana-monasca, documentation-suse-openstack-cloud, openstack-ec2-api, openstack-heat-templates, python-Django, python-monasca-common, rubygem-redcarpet, rubygem-puma contains the following fixes: Security fixes included in this update: rubygem-redcarpet: CVE-2020-26298: Fixed XSS via HTML escaping when processing quotes. (bsc#1180837) rubygem-puma: CVE-2021-41136: Fixed build of the Java state machine for parsing HTTP. (bsc#1191681) Non-security fixes included in this update: Changes in ardana-ansible: * Patch service.py to skip blank lines. Changes in ardana-monasca: * Use specific TLS versions for monasca-thresh DB connections. (SOC-11543) Changes in documentation-suse-openstack-cloud:

References

#1180837 #1191681 SOC-11543

Cross- CVE-2020-26298 CVE-2021-41136

CVSS scores:

CVE-2020-26298 (NVD) : 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CVE-2020-26298 (SUSE): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CVE-2021-41136 (NVD) : 3.7 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N

CVE-2021-41136 (SUSE): 3.7 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N

Affected Products:

SUSE OpenStack Cloud Crowbar 8

SUSE OpenStack Cloud 8

HPE Helion Openstack 8

https://www.suse.com/security/cve/CVE-2020-26298.html

https://www.suse.com/security/cve/CVE-2021-41136.html

https://bugzilla.suse.com/1180837

https://bugzilla.suse.com/1191681

Announcement ID: SUSE-SU-2021:3728-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.