Security update for ceph
This update for ceph fixes the following issues: Security issues fixed: - CVE-2019-3821: civetweb: fix file descriptor leak (bsc#1125080) - CVE-2018-16889: rgw: sanitize customer encryption keys from log output in v4 auth (bsc#1121567) Non-security issues fixed: - install grafana dashboards world readable (bsc#1136110) - upgrade results in cluster outage (bsc#1132396) - ceph status reports 'HEALTH_WARN 3 monitors have not enabled msgr2' (bsc#1124957) - Dashboard: Opening tcmu-runner perf counters results in a 404 (bsc#1135388) - RadosGW stopped expiring objects (bsc#1133139) - Ceph does not recover when rebuilding every OSD (bsc#1133461)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for ceph fixes the following issues: Security issues fixed: - CVE-2019-3821: civetweb: fix file descriptor leak (bsc#1125080) - CVE-2018-16889: rgw: sanitize customer encryption keys from log output in v4 auth (bsc#1121567) Non-security issues fixed: - install grafana dashboards world readable (bsc#1136110) - upgrade results in cluster outage (bsc#1132396) - ceph status reports 'HEALTH_WARN 3 monitors have not enabled msgr2' (bsc#1124957) - Dashboard: Opening tcmu-runner perf counters results in a 404 (bsc#1135388) - RadosGW stopped expiring objects (bsc#1133139) - Ceph does not recover when rebuilding every OSD (bsc#1133461)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1121567
- https://bugzilla.suse.com/1123360
- https://bugzilla.suse.com/1124957
- https://bugzilla.suse.com/1125080
- https://bugzilla.suse.com/1125899
- https://bugzilla.suse.com/1131984
- https://bugzilla.suse.com/1132396
- https://bugzilla.suse.com/1133139
- https://bugzilla.suse.com/1133461
- https://bugzilla.suse.com/1135030
- https://bugzilla.suse.com/1135219
- https://bugzilla.suse.com/1135221
- https://bugzilla.suse.com/1135388
- https://bugzilla.suse.com/1136110
- https://www.suse.com/security/cve/CVE-2018-16889
- https://www.suse.com/security/cve/CVE-2019-3821
- https://www.suse.com/support/update/announcement/2019/suse-su-20192049-1/