Oval Definition:oval:org.opensuse.security:def:58407
Revision Date:2020-12-01Version:1
Title:Security update for crowbar-core, crowbar-openstack, openstack-horizon-plugin-monasca-ui, openstack-monasca-api, openstack-monasca-log-api, openstack-neutron, rubygem-puma, rubygem-rest-client (Moderate)
Description:

This update for crowbar-core, crowbar-openstack, openstack-horizon-plugin-monasca-ui, openstack-monasca-api, openstack-monasca-log-api, openstack-neutron, rubygem-puma, rubygem-rest-client contains the following fixes:

Security issue fixed for rubygem-puma:

- CVE-2019-16770: Fixed a potential denial of service in Puma's reactor (bsc#1158675, jsc#SOC-10999)

Security issue fixed for rubygem-rest-client:

- CVE-2015-3448: Fixed a plain text local password disclosure. (bsc#917802)

Updates for crowbar-core: - Update to version 4.0+git.1574788924.e4a6aeb0c: * Allow pacemaker remotes for upgrade (SOC-10133)

- Update to version 4.0+git.1574713660.972029d1a: * Ignore CVE-2019-13117 in CI builds (bsc#1157028)

Updates for crowbar-openstack: - Update to version 4.0+git.1574869671.9c7bade2d: * tempest: configure Kibana version (SOC-10131)

- Update to version 4.0+git.1574764112.c260c70e5: * horizon: install lbaas horizon dashboard (SOC-10883)

Updates for openstack-horizon-plugin-monasca-ui: - Refresh allow-raw-grafana-links.patch - update to version 1.5.5~dev3 * Replace openstack.org git:// URLs with https:// * Fix the partial missing metrics in Create Alarm Definition flow * import zuul job settings from project-config * Fix incorrect splitting of dimension in ProxyView * Fix Alarm status Panel on Overview page * Change IntegerField to ChoiceField for notification period * Imported Translations from Zanata * Display unique metric names for alarm * Fix Alarm Details section in Alarm History view * Fix validators for creating and editing notifications * Center the text for the button Deterministic * Adding title to Filter Alarms pop-up * Fix misleading validation error * Fix nit found in monasca-ui * Fix Breadcrumbs * Fix description for name field * Fixing 'Create Alarm Definition' for IE11 * Imported Translations from Zanata

Updates to openstack-monasca-api: - added fix-metric-name-offset.patch (SOC-10131) - removed 0001-Fix-InfluxDB-repository-list_dimension_values-to-sup.patch (merged upstream) - update to version 1.7.1~dev18 * Replace openstack.org git:// URLs with https:// * import zuul job settings from project-config * Upgrade Apache Storm to 1.0.6 * Zuul: Remove project name

Updates to openstack-monasca-log-api: - added fix-tempest-region.patch (SOC-10131) - update to version 1.4.3~dev3 * Replace openstack.org git:// URLs with https:// * import zuul job settings from project-config * Avoid tox\_install.sh for constraints support

Updates to openstack-neutron: - neutron: Remove stop action from ovs-cleanup (bsc#1157482) backport of https://review.opendev.org/#/c/695867/
Family:unixClass:patch
Status:Reference(s):1005522
1005523
1005524
1005525
1005526
1005527
1005528
1012382
1022805
1032680
1042286
1044887
1044894
1054028
1056995
1062604
1064232
1065364
1075697
1082519
1082828
1082863
1082943
1083125
1084536
1085042
1085447
1088810
1089066
1090368
1090646
1090869
1092903
1094466
1095344
1096547
1097104
1098599
1099597
1099811
1099813
1099844
1099845
1099846
1099849
1099863
1099864
1099922
1099993
1099999
1100000
1100001
1100152
1102517
1102715
1102870
1102959
1103445
1104319
1104495
1105292
1105296
1105322
1105348
1105396
1105402
1105536
1106016
1106095
1106369
1106509
1106511
1106512
1106594
1106989
1106996
1107609
1107689
1107735
1107829
1107966
1108145
1108239
1108399
1109137
1109330
1109333
1110286
1117645
1119019
1119947
1120381
1120691
1121698
1121805
1122033
1122821
1124365
1124366
1124368
1124728
1124729
1124732
1124734
1124735
1125315
1127155
1127758
1127961
1128166
1128378
1128649
1129080
1129179
1129186
1130330
1131317
1132053
1132054
1132060
1144903
1153108
1153158
1153161
1157028
1157482
1158675
1174157
1175259
903543
917802
979907
997857
CVE-2015-3448
CVE-2015-8871
CVE-2016-2399
CVE-2016-5542
CVE-2016-5554
CVE-2016-5556
CVE-2016-5568
CVE-2016-5573
CVE-2016-5582
CVE-2016-5597
CVE-2016-7163
CVE-2017-11462
CVE-2017-13166
CVE-2017-15130
CVE-2017-7375
CVE-2017-7376
CVE-2018-10853
CVE-2018-1087
CVE-2018-10876
CVE-2018-10877
CVE-2018-10878
CVE-2018-10879
CVE-2018-10880
CVE-2018-10881
CVE-2018-10882
CVE-2018-10883
CVE-2018-10902
CVE-2018-10938
CVE-2018-10940
CVE-2018-12896
CVE-2018-13093
CVE-2018-13094
CVE-2018-13095
CVE-2018-14617
CVE-2018-14633
CVE-2018-14678
CVE-2018-15572
CVE-2018-15594
CVE-2018-16276
CVE-2018-16412
CVE-2018-16413
CVE-2018-16644
CVE-2018-16658
CVE-2018-16884
CVE-2018-17182
CVE-2018-20467
CVE-2018-6554
CVE-2018-6555
CVE-2018-7480
CVE-2018-7757
CVE-2018-8781
CVE-2018-8897
CVE-2018-9363
CVE-2019-10220
CVE-2019-10650
CVE-2019-11007
CVE-2019-11008
CVE-2019-11009
CVE-2019-13117
CVE-2019-16770
CVE-2019-17133
CVE-2019-17639
CVE-2019-2024
CVE-2019-3838
CVE-2019-6974
CVE-2019-7175
CVE-2019-7221
CVE-2019-7222
CVE-2019-7395
CVE-2019-7397
CVE-2019-7398
CVE-2019-9213
CVE-2019-9956
CVE-2020-14556
CVE-2020-14577
CVE-2020-14578
CVE-2020-14579
CVE-2020-14581
CVE-2020-14583
CVE-2020-14593
CVE-2020-14621
SUSE-SU-2016:2953-1
SUSE-SU-2017:0610-1
SUSE-SU-2017:2144-1
SUSE-SU-2017:2659-1
SUSE-SU-2018:1505-1
SUSE-SU-2018:2632-2
SUSE-SU-2018:3084-1
SUSE-SU-2019:0828-1
SUSE-SU-2020:0081-1
SUSE-SU-2020:2461-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND Package Information
  • bash-4.4-lp150.7 is installed
  • OR bash-doc-4.4-lp150.7 is installed
  • OR bash-lang-4.4-lp150.7 is installed
  • OR libreadline7-7.0-lp150.7 is installed
  • OR readline-doc-7.0-lp150.7 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND clementine-1.3.1-lp151.3.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND Package Information
  • libxml2-2.9.4-45 is installed
  • OR libxml2-2-2.9.4-45 is installed
  • OR libxml2-2-32bit-2.9.4-45 is installed
  • OR libxml2-doc-2.9.4-45 is installed
  • OR libxml2-tools-2.9.4-45 is installed
  • OR python-libxml2-2.9.4-45 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND Package Information
  • dovecot22-2.2.31-19.11 is installed
  • OR dovecot22-backend-mysql-2.2.31-19.11 is installed
  • OR dovecot22-backend-pgsql-2.2.31-19.11 is installed
  • OR dovecot22-backend-sqlite-2.2.31-19.11 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND Package Information
  • ImageMagick-6.8.8.1-71.108 is installed
  • OR ImageMagick-config-6-SUSE-6.8.8.1-71.108 is installed
  • OR ImageMagick-config-6-upstream-6.8.8.1-71.108 is installed
  • OR libMagickCore-6_Q16-1-6.8.8.1-71.108 is installed
  • OR libMagickWand-6_Q16-1-6.8.8.1-71.108 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND Package Information
  • kgraft-patch-4_4_74-92_29-default-11-2 is installed
  • OR kgraft-patch-SLE12-SP2_Update_10-11-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND Package Information
  • dovecot22-2.2.30.2-14 is installed
  • OR dovecot22-backend-mysql-2.2.30.2-14 is installed
  • OR dovecot22-backend-pgsql-2.2.30.2-14 is installed
  • OR dovecot22-backend-sqlite-2.2.30.2-14 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND Package Information
  • libpython3_4m1_0-3.4.6-25.29 is installed
  • OR python3-3.4.6-25.29 is installed
  • OR python3-base-3.4.6-25.29 is installed
  • OR python3-curses-3.4.6-25.29 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • kgraft-patch-4_4_156-94_61-default-7-2 is installed
  • OR kgraft-patch-SLE12-SP3_Update_19-7-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND gd-2.1.0-24.9 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • MozillaFirefox-52.9.0esr-109.38 is installed
  • OR MozillaFirefox-translations-52.9.0esr-109.38 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND Package Information
  • crowbar-core-4.0+git.1574788924.e4a6aeb0c-9.60 is installed
  • OR crowbar-core-branding-upstream-4.0+git.1574788924.e4a6aeb0c-9.60 is installed
  • OR crowbar-openstack-4.0+git.1574869671.9c7bade2d-9.65 is installed
  • OR grafana-monasca-ui-drilldown-1.5.5~dev3-8 is installed
  • OR openstack-horizon-plugin-monasca-ui-1.5.5~dev3-8 is installed
  • OR openstack-monasca-api-1.7.1~dev18-12 is installed
  • OR openstack-monasca-log-api-1.4.3~dev3-5 is installed
  • OR openstack-neutron-9.4.2~dev21-7.38 is installed
  • OR openstack-neutron-dhcp-agent-9.4.2~dev21-7.38 is installed
  • OR openstack-neutron-doc-9.4.2~dev21-7.38 is installed
  • OR openstack-neutron-ha-tool-9.4.2~dev21-7.38 is installed
  • OR openstack-neutron-l3-agent-9.4.2~dev21-7.38 is installed
  • OR openstack-neutron-linuxbridge-agent-9.4.2~dev21-7.38 is installed
  • OR openstack-neutron-macvtap-agent-9.4.2~dev21-7.38 is installed
  • OR openstack-neutron-metadata-agent-9.4.2~dev21-7.38 is installed
  • OR openstack-neutron-metering-agent-9.4.2~dev21-7.38 is installed
  • OR openstack-neutron-openvswitch-agent-9.4.2~dev21-7.38 is installed
  • OR openstack-neutron-server-9.4.2~dev21-7.38 is installed
  • OR python-horizon-plugin-monasca-ui-1.5.5~dev3-8 is installed
  • OR python-monasca-api-1.7.1~dev18-12 is installed
  • OR python-monasca-log-api-1.4.3~dev3-5 is installed
  • OR python-neutron-9.4.2~dev21-7.38 is installed
  • OR ruby2.1-rubygem-puma-2.16.0-4.3 is installed
  • OR rubygem-puma-2.16.0-4.3 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND Package Information
  • glibc-2.22-62.22 is installed
  • OR glibc-32bit-2.22-62.22 is installed
  • OR glibc-devel-2.22-62.22 is installed
  • OR glibc-devel-32bit-2.22-62.22 is installed
  • OR glibc-html-2.22-62.22 is installed
  • OR glibc-i18ndata-2.22-62.22 is installed
  • OR glibc-info-2.22-62.22 is installed
  • OR glibc-locale-2.22-62.22 is installed
  • OR glibc-locale-32bit-2.22-62.22 is installed
  • OR glibc-profile-2.22-62.22 is installed
  • OR glibc-profile-32bit-2.22-62.22 is installed
  • OR nscd-2.22-62.22 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND python-Django-1.11.11-3.3 is installed
  • BACK