FlawAtlas
Search the atlas
SUSE-SU-2023:2378-1 Not scored

Security update for openstack-heat, openstack-swift, python-Werkzeug

This update for openstack-heat, openstack-swift, python-Werkzeug contains the following fixes: Security fixes included in this update: openstack-heat: - CVE-2023-1625: Fixed an issue where parameter values marked as 'hidden' would be shown in the stack's environment (bsc#1209774). openstack-swift: - CVE-2022-47950: Fixed a local file disclosure that could be triggered by an authenticated attacker by supplying a malicious XML (bnc#1207035). python-Werkzeug: - CVE-2023-25577: Fixed an unbounded resource usage when parsing multipart forms with many fields (bsc#1208283). Non security changes on this update: Changes in openstack-heat: - Honor 'hidden' parameter in 'stack environment show' command. (bsc#1209774, CVE-2023-1625) Changes in openstack-swift: - Prevent XXE injections in API. (bsc#1207035, CVE-2022-47950) Changes in python-Werkzeug; - Limit maximum number of multipart form parts. (bsc#1208283, CVE-2023-25577)

Exploit probability Not scored
Published June 5, 2023
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:OpenStack Cloud 9 openstack-heat
SUSE:OpenStack Cloud 9 openstack-swift
SUSE:OpenStack Cloud 9 python-Werkzeug
SUSE:OpenStack Cloud 9 venv-openstack-designate
SUSE:OpenStack Cloud 9 venv-openstack-heat
SUSE:OpenStack Cloud 9 venv-openstack-keystone
SUSE:OpenStack Cloud 9 venv-openstack-magnum
SUSE:OpenStack Cloud 9 venv-openstack-octavia
SUSE:OpenStack Cloud 9 venv-openstack-sahara
SUSE:OpenStack Cloud 9 venv-openstack-swift
SUSE:OpenStack Cloud Crowbar 9 openstack-heat
SUSE:OpenStack Cloud Crowbar 9 openstack-swift
SUSE:OpenStack Cloud Crowbar 9 python-Werkzeug

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2023:2378-1

This update for openstack-heat, openstack-swift, python-Werkzeug contains the following fixes: Security fixes included in this update: openstack-heat: - CVE-2023-1625: Fixed an issue where parameter values marked as 'hidden' would be shown in the stack's environment (bsc#1209774). openstack-swift: - CVE-2022-47950: Fixed a local file disclosure that could be triggered by an authenticated attacker by supplying a malicious XML (bnc#1207035). python-Werkzeug: - CVE-2023-25577: Fixed an unbounded resource usage when parsing multipart forms with many fields (bsc#1208283). Non security changes on this update: Changes in openstack-heat: - Honor 'hidden' parameter in 'stack environment show' command. (bsc#1209774, CVE-2023-1625) Changes in openstack-swift: - Prevent XXE injections in API. (bsc#1207035, CVE-2022-47950) Changes in python-Werkzeug; - Limit maximum number of multipart form parts. (bsc#1208283, CVE-2023-25577)

View original source

05 / REFERENCES

Further evidence