Oval Definition:oval:org.opensuse.security:def:93202
Revision Date:2021-05-04Version:1
Title:Security update for ceph (Important)
Description:

This update for ceph fixes the following issues:

- ceph was updated to 14.2.20-402-g6aa76c6815: * CVE-2021-20288: Fixed unauthorized global_id reuse (bsc#1183074). * CVE-2020-25678: Do not add sensitive information in Ceph log files (bsc#1178905). * CVE-2020-27839: Use secure cookies to store JWT Token (bsc#1179997). * mgr/dashboard: prometheus alerting: add some leeway for package drops and errors (bsc#1145463) * mon: have 'mon stat' output json as well (bsc#1174466) * rpm: ceph-mgr-dashboard recommends python3-saml on SUSE (bsc#1177200) * mgr/dashboard: Display a warning message in Dashboard when debug mode is enabled (bsc#1178235) * rgw: cls/user: set from_index for reset stats calls (bsc#1178837) * mgr/dashboard: Disable TLS 1.0 and 1.1 (bsc#1178860) * bluestore: provide a different name for fallback allocator (bsc#1180118) * test/run-cli-tests: use cram from github (bsc#1181378) * mgr/dashboard: fix 'Python2 Cookie module import fails on Python3' (bsc#1183487) * common: make ms_bind_msgr2 default to 'false' (bsc#1180594)
Family:unixClass:patch
Status:Reference(s):1145463
1174466
1177200
1178235
1178837
1178860
1178905
1179997
1180118
1180594
1181378
1183074
1183487
CVE-2020-25678
CVE-2020-27839
CVE-2021-20288
SUSE-SU-2021:1473-1
Platform(s):SUSE Manager Server 4.0
Product(s):
Definition Synopsis
  • SUSE Manager Server 4.0 is installed
  • AND Package Information
  • ceph-common-14.2.20.402+g6aa76c6815-3.60.1 is installed
  • OR libcephfs-devel-14.2.20.402+g6aa76c6815-3.60.1 is installed
  • OR libcephfs2-14.2.20.402+g6aa76c6815-3.60.1 is installed
  • OR librados-devel-14.2.20.402+g6aa76c6815-3.60.1 is installed
  • OR librados2-14.2.20.402+g6aa76c6815-3.60.1 is installed
  • OR libradospp-devel-14.2.20.402+g6aa76c6815-3.60.1 is installed
  • OR librbd-devel-14.2.20.402+g6aa76c6815-3.60.1 is installed
  • OR librbd1-14.2.20.402+g6aa76c6815-3.60.1 is installed
  • OR librgw-devel-14.2.20.402+g6aa76c6815-3.60.1 is installed
  • OR librgw2-14.2.20.402+g6aa76c6815-3.60.1 is installed
  • OR python3-ceph-argparse-14.2.20.402+g6aa76c6815-3.60.1 is installed
  • OR python3-cephfs-14.2.20.402+g6aa76c6815-3.60.1 is installed
  • OR python3-rados-14.2.20.402+g6aa76c6815-3.60.1 is installed
  • OR python3-rbd-14.2.20.402+g6aa76c6815-3.60.1 is installed
  • OR python3-rgw-14.2.20.402+g6aa76c6815-3.60.1 is installed
  • OR rados-objclass-devel-14.2.20.402+g6aa76c6815-3.60.1 is installed
  • BACK