FlawAtlas
Search the atlas
SUSE-SU-2019:3068-1 Not scored

Security update for ardana-db, ardana-keystone, ardana-neutron, ardana-nova, crowbar-core, crowbar-openstack, crowbar-ui, openstack-barbican, openstack-heat-templates, openstack-keystone, openstack-neutron, openstack-neutron-gbp, openstack-neutron-lbaas, openstack-nova, openstack-octavia, openstack-sahara, python-psutil, release-notes-suse-openstack-cloud

This update for ardana-db, ardana-keystone, ardana-neutron, ardana-nova, crowbar-core, crowbar-openstack, crowbar-ui, openstack-barbican, openstack-heat-templates, openstack-keystone, openstack-neutron, openstack-neutron-gbp, openstack-neutron-lbaas, openstack-nova, openstack-octavia, openstack-sahara, python-psutil, release-notes-suse-openstack-cloud fixes the following issues: Security fix for openstack-octavia: - CVE-2019-17134: Fixed an issue where Octavia Amphora-Agent not requiring Client-Certificate (bsc#1153304). Security fix for python-psutil: - CVE-2019-18874: Fixed a double-free vulnerability occured during converting system data into a Python object (bsc#1155089). - Update to version 9.0+git.1572311426.a6dc2fd: * Align Crowbar and Ardana MariaDB configs (SOC-10094) - Update to version 9.0+git.1573069087.15ffd1c: * enable debug and insecure_debug on demand (SOC-10934) - Update to version 9.0+git.1572019823.6650494: * Correctly setup ardana_notify_... fact (SOC-10902) - Update to version 9.0+git.1572618171.4460843: * Update gerrit FQDN in .gitreview (SOC-9140) - Update to version 6.0+git.1573825081.b1caf60f1: * Update the testsuite for new upgrade method (SOC-10761) * upgrade: cold start nova before live migration (SOC-10761) - Update to version 6.0+git.1573131992.3c660b413: * [upgrade] Call finalize_nodes_upgrade at the very end (bsc#1155942) - Update to version 6.0+git.1573051151.3495e0e94: * Allow enabling bpdu-forwarding on OVS bridges (SOC-9172) - Update to version 6.0+git.1573754820.dd036ef77: * neutron: use octavia-api admin VIP URI for lbaasv2 (SOC-10906) * octavia: handle certificate ownership in barclamp (SOC-10906) * octavia: add SSL support to octavia-api (SOC-10906) - Update to version 6.0+git.1573174019.9965ae9b8: * designate: change default configuration (SOC-10899) - Update to version 6.0+git.1572855359.8efafea01: * Make sure the input file with ssh key exists (SOC-10133) - Update to version 6.0+git.1572636244.e12406629: * Change order of Octavia to 102 (SOC-10289) - Update to version 6.0+git.1572470261.49c0affe1: * designate: move keystone resource lookup to convergence (SOC-10887) - Update to version 1.3.0+git.1572871359.50fc6087: * Add title for XEN compute nodes precheck (SOC-10495) - Update to version barbican-7.0.1.dev21: * Fix duplicate paths in secret hrefs * Fix the bug of pep8 and building api-guide * OpenDev Migration Patch - Update to version barbican-7.0.1.dev21: * Fix duplicate paths in secret hrefs * Fix the bug of pep8 and building api-guide * OpenDev Migration Patch - remove 0001-Fix-duplicate-paths-in-secret-hrefs.patch as it had landed upstream - Replace openstack.org git:// URLs with https:// - Update to version keystone-14.1.1.dev28: * Allows to use application credentials through group membership - Update to version keystone-14.1.1.dev28: * Allows to use application credentials through group membership - Update to version neutron-13.0.6.dev8: * Retry creating iptables managers and adding metering rules - Update to version neutron-13.0.6.dev6: * Increase timeout when waiting for dnsmasq enablement - Update to version neutron-13.0.6.dev4: * Log OVS firewall conjunction creation - Update to version neutron-13.0.6.dev8: * Retry creating iptables managers and adding metering rules - Update to version neutron-13.0.6.dev6: * Increase timeout when waiting for dnsmasq enablement - Update to version neutron-13.0.6.dev4: * Log OVS firewall conjunction creation - Update to version group-based-policy-5.0.1.dev476: * Provide a control knob to use the internal EP interface * Send port notifications when host\_route is getting updated - Update to version group-based-policy-5.0.1.dev473: * Fix pep8 failures seen on submitted patches - Update to version neutron-lbaas-13.0.1.dev16: * 'lbaas delete l7 rule' Parameter Passing Error - Update to version neutron-lbaas-13.0.1.dev16: * 'lbaas delete l7 rule' Parameter Passing Error - Update to version nova-18.2.4.dev22: * Revert 'openstack server create' to 'nova boot' in nova docs * doc: fix and clarify --block-device usage in user docs - Update to version nova-18.2.4.dev20: * Avoid error 500 on shelve task\_state race - Update to version nova-18.2.4.dev19: * libvirt: Ignore volume exceptions during post\_live\_migration - Update to version nova-18.2.4.dev22: * Revert 'openstack server create' to 'nova boot' in nova docs * doc: fix and clarify --block-device usage in user docs - Update to version nova-18.2.4.dev20: * Avoid error 500 on shelve task\_state race - Update to version nova-18.2.4.dev19: * libvirt: Ignore volume exceptions during post\_live\_migration - Update to version octavia-3.2.1.dev3: * Improve the error message for bad pkcs12 bundles - Update to version octavia-3.2.1.dev2: * ipvsadm '--exact' arg to ensure outputs are ints - Update to version sahara-9.0.2.dev14: * Fixing image creation * Check MariaDB installation - Update to version sahara-9.0.2.dev14: * Fixing image creation * Check MariaDB installation - Update to version 9.20191025: * support OpenID Connect (SOC-10510)

Exploit probability Not scored
Published November 26, 2019
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:OpenStack Cloud Crowbar 9 openstack-octavia
SUSE:OpenStack Cloud Crowbar 9 release-notes-suse-openstack-cloud
SUSE:OpenStack Cloud Crowbar 9 crowbar-openstack
SUSE:OpenStack Cloud Crowbar 9 openstack-barbican
SUSE:OpenStack Cloud Crowbar 9 openstack-neutron
SUSE:OpenStack Cloud Crowbar 9 python-psutil
SUSE:OpenStack Cloud 9 venv-openstack-cinder
SUSE:OpenStack Cloud 9 openstack-heat-templates
SUSE:OpenStack Cloud 9 ardana-neutron
SUSE:OpenStack Cloud 9 openstack-barbican
SUSE:OpenStack Cloud 9 openstack-neutron
SUSE:OpenStack Cloud Crowbar 9 openstack-neutron-lbaas
SUSE:OpenStack Cloud 9 openstack-keystone
SUSE:OpenStack Cloud 9 openstack-neutron-gbp
SUSE:OpenStack Cloud 9 venv-openstack-monasca-ceilometer
SUSE:OpenStack Cloud 9 venv-openstack-sahara
SUSE:OpenStack Cloud 9 venv-openstack-nova
SUSE:OpenStack Cloud 9 venv-openstack-heat
SUSE:OpenStack Cloud 9 python-psutil
SUSE:OpenStack Cloud 9 venv-openstack-barbican
SUSE:OpenStack Cloud Crowbar 9 openstack-neutron-gbp
SUSE:OpenStack Cloud 9 openstack-sahara
SUSE:OpenStack Cloud 9 openstack-neutron-lbaas
SUSE:OpenStack Cloud 9 venv-openstack-manila
SUSE:OpenStack Cloud 9 venv-openstack-neutron
SUSE:OpenStack Cloud 9 venv-openstack-octavia
SUSE:OpenStack Cloud 9 openstack-octavia
SUSE:OpenStack Cloud Crowbar 9 openstack-sahara
SUSE:OpenStack Cloud 9 release-notes-suse-openstack-cloud
SUSE:OpenStack Cloud Crowbar 9 crowbar-ui
SUSE:OpenStack Cloud 9 venv-openstack-keystone
SUSE:OpenStack Cloud 9 ardana-keystone
SUSE:OpenStack Cloud Crowbar 9 openstack-heat-templates
SUSE:OpenStack Cloud Crowbar 9 openstack-keystone
SUSE:OpenStack Cloud Crowbar 9 openstack-nova
SUSE:OpenStack Cloud 9 venv-openstack-magnum
SUSE:OpenStack Cloud 9 ardana-db
SUSE:OpenStack Cloud 9 ardana-nova
SUSE:OpenStack Cloud Crowbar 9 crowbar-core
SUSE:OpenStack Cloud 9 venv-openstack-designate
SUSE:OpenStack Cloud 9 openstack-nova

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2019:3068-1

This update for ardana-db, ardana-keystone, ardana-neutron, ardana-nova, crowbar-core, crowbar-openstack, crowbar-ui, openstack-barbican, openstack-heat-templates, openstack-keystone, openstack-neutron, openstack-neutron-gbp, openstack-neutron-lbaas, openstack-nova, openstack-octavia, openstack-sahara, python-psutil, release-notes-suse-openstack-cloud fixes the following issues: Security fix for openstack-octavia: - CVE-2019-17134: Fixed an issue where Octavia Amphora-Agent not requiring Client-Certificate (bsc#1153304). Security fix for python-psutil: - CVE-2019-18874: Fixed a double-free vulnerability occured during converting system data into a Python object (bsc#1155089). - Update to version 9.0+git.1572311426.a6dc2fd: * Align Crowbar and Ardana MariaDB configs (SOC-10094) - Update to version 9.0+git.1573069087.15ffd1c: * enable debug and insecure_debug on demand (SOC-10934) - Update to version 9.0+git.1572019823.6650494: * Correctly setup ardana_notify_... fact (SOC-10902) - Update to version 9.0+git.1572618171.4460843: * Update gerrit FQDN in .gitreview (SOC-9140) - Update to version 6.0+git.1573825081.b1caf60f1: * Update the testsuite for new upgrade method (SOC-10761) * upgrade: cold start nova before live migration (SOC-10761) - Update to version 6.0+git.1573131992.3c660b413: * [upgrade] Call finalize_nodes_upgrade at the very end (bsc#1155942) - Update to version 6.0+git.1573051151.3495e0e94: * Allow enabling bpdu-forwarding on OVS bridges (SOC-9172) - Update to version 6.0+git.1573754820.dd036ef77: * neutron: use octavia-api admin VIP URI for lbaasv2 (SOC-10906) * octavia: handle certificate ownership in barclamp (SOC-10906) * octavia: add SSL support to octavia-api (SOC-10906) - Update to version 6.0+git.1573174019.9965ae9b8: * designate: change default configuration (SOC-10899) - Update to version 6.0+git.1572855359.8efafea01: * Make sure the input file with ssh key exists (SOC-10133) - Update to version 6.0+git.1572636244.e12406629: * Change order of Octavia to 102 (SOC-10289) - Update to version 6.0+git.1572470261.49c0affe1: * designate: move keystone resource lookup to convergence (SOC-10887) - Update to version 1.3.0+git.1572871359.50fc6087: * Add title for XEN compute nodes precheck (SOC-10495) - Update to version barbican-7.0.1.dev21: * Fix duplicate paths in secret hrefs * Fix the bug of pep8 and building api-guide * OpenDev Migration Patch - Update to version barbican-7.0.1.dev21: * Fix duplicate paths in secret hrefs * Fix the bug of pep8 and building api-guide * OpenDev Migration Patch - remove 0001-Fix-duplicate-paths-in-secret-hrefs.patch as it had landed upstream - Replace openstack.org git:// URLs with https:// - Update to version keystone-14.1.1.dev28: * Allows to use application credentials through group membership - Update to version keystone-14.1.1.dev28: * Allows to use application credentials through group membership - Update to version neutron-13.0.6.dev8: * Retry creating iptables managers and adding metering rules - Update to version neutron-13.0.6.dev6: * Increase timeout when waiting for dnsmasq enablement - Update to version neutron-13.0.6.dev4: * Log OVS firewall conjunction creation - Update to version neutron-13.0.6.dev8: * Retry creating iptables managers and adding metering rules - Update to version neutron-13.0.6.dev6: * Increase timeout when waiting for dnsmasq enablement - Update to version neutron-13.0.6.dev4: * Log OVS firewall conjunction creation - Update to version group-based-policy-5.0.1.dev476: * Provide a control knob to use the internal EP interface * Send port notifications when host\_route is getting updated - Update to version group-based-policy-5.0.1.dev473: * Fix pep8 failures seen on submitted patches - Update to version neutron-lbaas-13.0.1.dev16: * 'lbaas delete l7 rule' Parameter Passing Error - Update to version neutron-lbaas-13.0.1.dev16: * 'lbaas delete l7 rule' Parameter Passing Error - Update to version nova-18.2.4.dev22: * Revert 'openstack server create' to 'nova boot' in nova docs * doc: fix and clarify --block-device usage in user docs - Update to version nova-18.2.4.dev20: * Avoid error 500 on shelve task\_state race - Update to version nova-18.2.4.dev19: * libvirt: Ignore volume exceptions during post\_live\_migration - Update to version nova-18.2.4.dev22: * Revert 'openstack server create' to 'nova boot' in nova docs * doc: fix and clarify --block-device usage in user docs - Update to version nova-18.2.4.dev20: * Avoid error 500 on shelve task\_state race - Update to version nova-18.2.4.dev19: * libvirt: Ignore volume exceptions during post\_live\_migration - Update to version octavia-3.2.1.dev3: * Improve the error message for bad pkcs12 bundles - Update to version octavia-3.2.1.dev2: * ipvsadm '--exact' arg to ensure outputs are ints - Update to version sahara-9.0.2.dev14: * Fixing image creation * Check MariaDB installation - Update to version sahara-9.0.2.dev14: * Fixing image creation * Check MariaDB installation - Update to version 9.20191025: * support OpenID Connect (SOC-10510)

View original source

05 / REFERENCES

Further evidence