Recommended update for ardana-horizon, ardana-logging, ardana-monasca, ardana-mq, ardana-osconfig, crowbar-ha, crowbar-openstack, kibana, openstack-neutron, openstack-nova, python-Django, release-notes-suse-openstack-cloud, sleshammer, spark
This update for ardana-horizon, ardana-logging, ardana-monasca, ardana-mq, ardana-osconfig, crowbar-ha, crowbar-openstack, kibana, openstack-neutron, openstack-nova, python-Django, release-notes-suse-openstack-cloud, sleshammer, spark fixes the following issues: Security fix from this update: python-Django1 - CVE-2021-3281: Fixed a potential directory traversal when extracting archives (bsc#1181379). Changes in ardana-horizon_Update: - Update to version 8.0+git.1610733160.0f577f4: * Add Fix for logfile permissions (bsc#1179189) Changes in ardana-logging_Update: - Update to version 8.0+git.1610573640.452aed1: * Remove some files from upgrade.yml (bsc#1179189) Changes in ardana-monasca_Update: - Update to version 8.0+git.1610740501.5dca121: * Add Fix for logfile permissions (bsc#1179189) Changes in ardana-mq_Update: - Update to version 8.0+git.1605176800.52cccfa: * Re-enable mirroring of fanout and reply queues (bsc#1177611) Changes in ardana-osconfig_Update: - Update to version 8.0+git.1610643571.91b88d6: * Remove SLES-12-SP3-LTSS repos (bsc#1180916) Changes in crowbar-ha: - Update to version 5.0+git.1610564036.b75ee1b: * [5.0] crowbar-pacemaker: Cluster member SSH key improvements Changes in crowbar-openstack: - Update to version 5.0+git.1610402513.08dca931e: * neutron: Fix handling of networks with non-ascii names (SOC-11429) - Update to version 5.0+git.1610372799.621afb999: * keystone: fix keystone node lookup (SOC-11333, bsc#1164838) Changes in kibana: - Add 0001-Configurable-custom-response-headers-for-server.patch (bsc#1171909, CVE-2020-10743) - Added kibana.yml symlink (bsc#1048688, FATE#323204) Changes in openstack-nova_Update: - Update to version nova-16.1.9.dev78: * [stable-only] Cap bandit to 1.6.2 Changes in python-Django_Update: - Add CVE-2021-3281.patch (bsc#1181379, CVE-2021-3281) * Fixes a potential directory traversal when extracting archives Changes in release-notes-suse-openstack-cloud: - Fix incorrect issue number for bsc#1179955 - Update to version 8.20201214: * Add workaround for secure boot issue when shim package is updated. (bsc#1179955) Changes in spark_Update: - Add _constraints to prevent build from running out of disk space. Changes in sleshammer: - Really drop etc/udev/rules.d/70-persistent-net.rules from the overlay it was still present in the tarball. (SOC-9288) - added ruby2.1-rubygem-crowbar-client providing crowbarctl
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for ardana-horizon, ardana-logging, ardana-monasca, ardana-mq, ardana-osconfig, crowbar-ha, crowbar-openstack, kibana, openstack-neutron, openstack-nova, python-Django, release-notes-suse-openstack-cloud, sleshammer, spark fixes the following issues: Security fix from this update: python-Django1 - CVE-2021-3281: Fixed a potential directory traversal when extracting archives (bsc#1181379). Changes in ardana-horizon_Update: - Update to version 8.0+git.1610733160.0f577f4: * Add Fix for logfile permissions (bsc#1179189) Changes in ardana-logging_Update: - Update to version 8.0+git.1610573640.452aed1: * Remove some files from upgrade.yml (bsc#1179189) Changes in ardana-monasca_Update: - Update to version 8.0+git.1610740501.5dca121: * Add Fix for logfile permissions (bsc#1179189) Changes in ardana-mq_Update: - Update to version 8.0+git.1605176800.52cccfa: * Re-enable mirroring of fanout and reply queues (bsc#1177611) Changes in ardana-osconfig_Update: - Update to version 8.0+git.1610643571.91b88d6: * Remove SLES-12-SP3-LTSS repos (bsc#1180916) Changes in crowbar-ha: - Update to version 5.0+git.1610564036.b75ee1b: * [5.0] crowbar-pacemaker: Cluster member SSH key improvements Changes in crowbar-openstack: - Update to version 5.0+git.1610402513.08dca931e: * neutron: Fix handling of networks with non-ascii names (SOC-11429) - Update to version 5.0+git.1610372799.621afb999: * keystone: fix keystone node lookup (SOC-11333, bsc#1164838) Changes in kibana: - Add 0001-Configurable-custom-response-headers-for-server.patch (bsc#1171909, CVE-2020-10743) - Added kibana.yml symlink (bsc#1048688, FATE#323204) Changes in openstack-nova_Update: - Update to version nova-16.1.9.dev78: * [stable-only] Cap bandit to 1.6.2 Changes in python-Django_Update: - Add CVE-2021-3281.patch (bsc#1181379, CVE-2021-3281) * Fixes a potential directory traversal when extracting archives Changes in release-notes-suse-openstack-cloud: - Fix incorrect issue number for bsc#1179955 - Update to version 8.20201214: * Add workaround for secure boot issue when shim package is updated. (bsc#1179955) Changes in spark_Update: - Add _constraints to prevent build from running out of disk space. Changes in sleshammer: - Really drop etc/udev/rules.d/70-persistent-net.rules from the overlay it was still present in the tarball. (SOC-9288) - added ruby2.1-rubygem-crowbar-client providing crowbarctl
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1048688
- https://bugzilla.suse.com/1164838
- https://bugzilla.suse.com/1177611
- https://bugzilla.suse.com/1179189
- https://bugzilla.suse.com/1179955
- https://bugzilla.suse.com/1180916
- https://bugzilla.suse.com/1181379
- https://www.suse.com/security/cve/CVE-2016-8611
- https://www.suse.com/security/cve/CVE-2020-10743
- https://www.suse.com/security/cve/CVE-2021-3281
- https://www.suse.com/support/update/announcement/-2021-351/suse-ru-20210351-1/