Security update for openstack-heat, openstack-swift, python-Werkzeug
This update for openstack-heat, openstack-swift, python-Werkzeug contains the following fixes: Security fixes included in this update: openstack-heat: - CVE-2023-1625: Fixed an issue where parameter values marked as 'hidden' would be shown in the stack's environment (bsc#1209774). openstack-swift: - CVE-2022-47950: Fixed a local file disclosure that could be triggered by an authenticated attacker by supplying a malicious XML (bnc#1207035). python-Werkzeug: - CVE-2023-25577: Fixed an unbounded resource usage when parsing multipart forms with many fields (bsc#1208283). Non security changes on this update: Changes in openstack-heat: - Honor 'hidden' parameter in 'stack environment show' command. (bsc#1209774, CVE-2023-1625) Changes in openstack-swift: - Prevent XXE injections in API. (bsc#1207035, CVE-2022-47950) Changes in python-Werkzeug; - Limit maximum number of multipart form parts. (bsc#1208283, CVE-2023-25577)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for openstack-heat, openstack-swift, python-Werkzeug contains the following fixes: Security fixes included in this update: openstack-heat: - CVE-2023-1625: Fixed an issue where parameter values marked as 'hidden' would be shown in the stack's environment (bsc#1209774). openstack-swift: - CVE-2022-47950: Fixed a local file disclosure that could be triggered by an authenticated attacker by supplying a malicious XML (bnc#1207035). python-Werkzeug: - CVE-2023-25577: Fixed an unbounded resource usage when parsing multipart forms with many fields (bsc#1208283). Non security changes on this update: Changes in openstack-heat: - Honor 'hidden' parameter in 'stack environment show' command. (bsc#1209774, CVE-2023-1625) Changes in openstack-swift: - Prevent XXE injections in API. (bsc#1207035, CVE-2022-47950) Changes in python-Werkzeug; - Limit maximum number of multipart form parts. (bsc#1208283, CVE-2023-25577)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1207035
- https://bugzilla.suse.com/1208283
- https://bugzilla.suse.com/1209774
- https://www.suse.com/security/cve/CVE-2022-47950
- https://www.suse.com/security/cve/CVE-2023-1625
- https://www.suse.com/security/cve/CVE-2023-25577
- https://www.suse.com/support/update/announcement/2023/suse-su-20232378-1/