Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2022:1729-1 Important: ardana-barbican and grafana Security Fixes

suse
Calendar Grey May 18, 2022
Dist Suse Esm H88
SUSE has released a crucial security update that tackles significant vulnerabilities in ardana-barbican and grafana to bolster overall system security.
An update that solves 17 vulnerabilities, contains two features and has one errata is now available

Summary

This update for ardana-barbican, grafana, openstack-barbican, openstack-cinder, openstack-heat-gbp, openstack-horizon-plugin-gbp-ui, openstack-ironic, openstack-keystone, openstack-neutron-gbp, python-lxml, release-notes-suse-openstack-cloud fixes the following issues: Security fixes included on the update: ardana-barbican: - Update policies to protect container secret access (SOC-11621) - Update policies to protect secret metadata access (SOC-11620) openstack-neutron: - CVE-2021-40085: Fixed arbitrary dnsmasq reconfiguration via extra_dhcp_opts (bsc#1189794). rubygem-sinatra: - CVE-2022-29970: Fixed path traversal possible outside of public_dir when serving static files (bsc#1199138). python-XStatic-jquery-ui:

References

#1118088 #1179534 #1184177 #1186380 #1189390

#1189794 #1192070 #1192073 #1192075 #1193597

#1193688 #1193752 #1194521 #1194551 #1194552

#1194952 #1194954 #1199138 SOC-11620 SOC-11621

Cross- CVE-2018-19787 CVE-2020-27783 CVE-2021-28957

CVE-2021-38155 CVE-2021-40085 CVE-2021-41182

CVE-2021-41183 CVE-2021-41184 CVE-2021-43813

CVE-2021-43818 CVE-2021-44716 CVE-2022-22815

CVE-2022-22816 CVE-2022-22817 CVE-2022-23451

CVE-2022-23452 CVE-2022-29970

CVSS scores:

CVE-2018-19787 (NVD) : 6.1 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CVE-2018-19787 (SUSE): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

CVE-2020-27783 (NVD) : 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CVE-2020-27783 (SUSE): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:1729-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here