Recommended update for ardana-horizon, ardana-logging, ardana-monasca, ardana-mq, ardana-osconfig, crowbar-ha, crowbar-openstack, kibana, openstack-neutron, openstack-nova, python-Django, release-note
An update that solves three vulnerabilities, contains 77 features and has four fixes can now be installed.
Description:
This update for ardana-horizon, ardana-logging, ardana-monasca, ardana-mq, ardana-osconfig, crowbar-ha, crowbar-openstack, kibana, openstack-neutron, openstack-nova, python-Django, release-notes-suse-openstack-cloud, sleshammer, spark fixes the following issues:
Security fix from this update: python-Django1 - CVE-2021-3281: Fixed a potential directory traversal when extracting archives (bsc#1181379).
Changes in ardana-horizon_Update: - Update to version 8.0+git.1610733160.0f577f4: * Add Fix for logfile permissions (bsc#1179189)
Changes in ardana-logging_Update: - Update to version 8.0+git.1610573640.452aed1: * Remove some files from upgrade.yml (bsc#1179189)
Changes in ardana-monasca_Update: - Update to version 8.0+git.1610740501.5dca121: * Add Fix for logfile permissions (bsc#1179189)
Changes in ardana-mq_Update: - Update to version 8.0+git.1605176800.52cccfa: * Re-enable mirroring of fanout and reply queues (bsc#1177611)
Changes in ardana-osconfig_Update: - Update to version 8.0+git.1610643571.91b88d6: * Remove SLES-12-SP3-LTSS repos (bsc#1180916)
Changes in crowbar-ha: - Update to version 5.0+git.1610564036.b75ee1b: * [5.0] crowbar-pacemaker: Cluster member SSH key improvements
Changes in crowbar-openstack: - Update to version 5.0+git.1610402513.08dca931e: * neutron: Fix handling of networks with non-ascii names (SOC-11429)
- Update to version 5.0+git.1610372799.621afb999:
- keystone: fix keystone node lookup (SOC-11333, bsc#1164838)
Changes in kibana: - Add 0001-Configurable-custom-response-headers-for-server.patch (bsc#1171909, CVE-2020-10743)
- Added kibana.yml symlink (bsc#1048688, FATE#323204)
Changes in openstack-nova_Update: - Update to version nova-16.1.9.dev78: * [stable-only] Cap bandit to 1.6.2
Changes in python-Django_Update: - Add CVE-2021-3281.patch (bsc#1181379, CVE-2021-3281) * Fixes a potential directory traversal when extracting archives
Changes in release-notes-suse-openstack-cloud: - Fix incorrect issue number for bsc#1179955 - Update to version 8.20201214: * Add workaround for secure boot issue when shim package is updated. (bsc#1179955)
Changes in spark_Update: - Add _constraints to prevent build from running out of disk space.
Changes in sleshammer: - Really drop etc/udev/rules.d/70-persistent-net.rules from the overlay it was still present in the tarball. (SOC-9288)
- added ruby2.1-rubygem-crowbar-client providing crowbarctl
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
HPE Helion OpenStack 8
zypper in -t patch HPE-Helion-OpenStack-8-2021-351=1
-
SUSE OpenStack Cloud 8
zypper in -t patch SUSE-OpenStack-Cloud-8-2021-351=1
-
SUSE OpenStack Cloud Crowbar 8
zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2021-351=1
Package List:
-
HPE Helion OpenStack 8 (noarch)
- spark-1.6.3-8.6.1
- openstack-nova-cells-16.1.9~dev78-3.45.1
- venv-openstack-nova-x86_64-16.1.9~dev78-11.34.1
- openstack-nova-placement-api-16.1.9~dev78-3.45.1
- venv-openstack-horizon-hpe-x86_64-12.0.5~dev6-14.34.1
- ardana-horizon-8.0+git.1610733160.0f577f4-3.21.1
- openstack-neutron-linuxbridge-agent-11.0.9~dev69-3.40.1
- openstack-nova-doc-16.1.9~dev78-3.45.1
- openstack-neutron-dhcp-agent-11.0.9~dev69-3.40.1
- openstack-neutron-server-11.0.9~dev69-3.40.1
- openstack-nova-consoleauth-16.1.9~dev78-3.45.1
- openstack-neutron-ha-tool-11.0.9~dev69-3.40.1
- venv-openstack-neutron-x86_64-11.0.9~dev69-13.36.1
- openstack-nova-vncproxy-16.1.9~dev78-3.45.1
- openstack-nova-serialproxy-16.1.9~dev78-3.45.1
- openstack-nova-compute-16.1.9~dev78-3.45.1
- ardana-osconfig-8.0+git.1610643571.91b88d6-3.52.1
- openstack-neutron-openvswitch-agent-11.0.9~dev69-3.40.1
- openstack-nova-console-16.1.9~dev78-3.45.1
- openstack-nova-conductor-16.1.9~dev78-3.45.1
- openstack-neutron-metering-agent-11.0.9~dev69-3.40.1
- python-Django-1.11.29-3.22.1
- openstack-neutron-11.0.9~dev69-3.40.1
- openstack-neutron-doc-11.0.9~dev69-3.40.1
- ardana-mq-8.0+git.1605176800.52cccfa-3.29.1
- python-neutron-11.0.9~dev69-3.40.1
- openstack-neutron-l3-agent-11.0.9~dev69-3.40.1
- openstack-nova-api-16.1.9~dev78-3.45.1
- ardana-monasca-8.0+git.1610740501.5dca121-3.27.1
- openstack-nova-scheduler-16.1.9~dev78-3.45.1
- openstack-neutron-metadata-agent-11.0.9~dev69-3.40.1
- release-notes-hpe-helion-openstack-8.20201214-3.29.1
- openstack-neutron-macvtap-agent-11.0.9~dev69-3.40.1
- ardana-logging-8.0+git.1610573640.452aed1-3.27.1
- python-nova-16.1.9~dev78-3.45.1
- openstack-nova-16.1.9~dev78-3.45.1
- openstack-nova-novncproxy-16.1.9~dev78-3.45.1
-
HPE Helion OpenStack 8 (x86_64)
- kibana-4.6.3-3.6.1
- kibana-debuginfo-4.6.3-3.6.1
-
SUSE OpenStack Cloud 8 (noarch)
- spark-1.6.3-8.6.1
- openstack-nova-cells-16.1.9~dev78-3.45.1
- venv-openstack-nova-x86_64-16.1.9~dev78-11.34.1
- openstack-nova-placement-api-16.1.9~dev78-3.45.1
- ardana-horizon-8.0+git.1610733160.0f577f4-3.21.1
- openstack-neutron-linuxbridge-agent-11.0.9~dev69-3.40.1
- openstack-nova-doc-16.1.9~dev78-3.45.1
- openstack-neutron-dhcp-agent-11.0.9~dev69-3.40.1
- openstack-neutron-server-11.0.9~dev69-3.40.1
- openstack-nova-consoleauth-16.1.9~dev78-3.45.1
- openstack-neutron-ha-tool-11.0.9~dev69-3.40.1
- venv-openstack-neutron-x86_64-11.0.9~dev69-13.36.1
- openstack-nova-vncproxy-16.1.9~dev78-3.45.1
- openstack-nova-serialproxy-16.1.9~dev78-3.45.1
- openstack-nova-compute-16.1.9~dev78-3.45.1
- release-notes-suse-openstack-cloud-8.20201214-3.29.1
- ardana-osconfig-8.0+git.1610643571.91b88d6-3.52.1
- openstack-neutron-openvswitch-agent-11.0.9~dev69-3.40.1
- openstack-nova-console-16.1.9~dev78-3.45.1
- openstack-nova-conductor-16.1.9~dev78-3.45.1
- openstack-neutron-metering-agent-11.0.9~dev69-3.40.1
- python-Django-1.11.29-3.22.1
- openstack-neutron-11.0.9~dev69-3.40.1
- openstack-neutron-doc-11.0.9~dev69-3.40.1
- ardana-mq-8.0+git.1605176800.52cccfa-3.29.1
- venv-openstack-horizon-x86_64-12.0.5~dev6-14.34.3
- python-neutron-11.0.9~dev69-3.40.1
- openstack-neutron-l3-agent-11.0.9~dev69-3.40.1
- openstack-nova-api-16.1.9~dev78-3.45.1
- ardana-monasca-8.0+git.1610740501.5dca121-3.27.1
- openstack-nova-scheduler-16.1.9~dev78-3.45.1
- openstack-neutron-metadata-agent-11.0.9~dev69-3.40.1
- openstack-neutron-macvtap-agent-11.0.9~dev69-3.40.1
- ardana-logging-8.0+git.1610573640.452aed1-3.27.1
- python-nova-16.1.9~dev78-3.45.1
- openstack-nova-16.1.9~dev78-3.45.1
- openstack-nova-novncproxy-16.1.9~dev78-3.45.1
-
SUSE OpenStack Cloud 8 (x86_64)
- kibana-4.6.3-3.6.1
- kibana-debuginfo-4.6.3-3.6.1
-
SUSE OpenStack Cloud Crowbar 8 (noarch)
- spark-1.6.3-8.6.1
- openstack-nova-cells-16.1.9~dev78-3.45.1
- sleshammer-debugsource-0.8.0-0.20.2
- sleshammer-s390x-0.8.0-0.20.2
- openstack-nova-placement-api-16.1.9~dev78-3.45.1
- openstack-neutron-linuxbridge-agent-11.0.9~dev69-3.40.1
- openstack-nova-doc-16.1.9~dev78-3.45.1
- openstack-neutron-dhcp-agent-11.0.9~dev69-3.40.1
- openstack-neutron-server-11.0.9~dev69-3.40.1
- openstack-nova-consoleauth-16.1.9~dev78-3.45.1
- openstack-neutron-ha-tool-11.0.9~dev69-3.40.1
- sleshammer-x86_64-0.8.0-0.20.2
- openstack-nova-vncproxy-16.1.9~dev78-3.45.1
- openstack-nova-serialproxy-16.1.9~dev78-3.45.1
- openstack-nova-compute-16.1.9~dev78-3.45.1
- release-notes-suse-openstack-cloud-8.20201214-3.29.1
- openstack-neutron-openvswitch-agent-11.0.9~dev69-3.40.1
- openstack-nova-console-16.1.9~dev78-3.45.1
- openstack-nova-conductor-16.1.9~dev78-3.45.1
- crowbar-openstack-5.0+git.1610402513.08dca931e-4.49.1
- openstack-neutron-metering-agent-11.0.9~dev69-3.40.1
- python-Django-1.11.29-3.22.1
- openstack-neutron-11.0.9~dev69-3.40.1
- openstack-neutron-doc-11.0.9~dev69-3.40.1
- sleshammer-ppc64le-0.8.0-0.20.2
- python-neutron-11.0.9~dev69-3.40.1
- openstack-neutron-l3-agent-11.0.9~dev69-3.40.1
- openstack-nova-api-16.1.9~dev78-3.45.1
- crowbar-ha-5.0+git.1610564036.b75ee1b-3.35.1
- openstack-nova-scheduler-16.1.9~dev78-3.45.1
- openstack-neutron-metadata-agent-11.0.9~dev69-3.40.1
- sleshammer-aarch64-0.8.0-0.20.2
- openstack-neutron-macvtap-agent-11.0.9~dev69-3.40.1
- python-nova-16.1.9~dev78-3.45.1
- openstack-nova-16.1.9~dev78-3.45.1
- openstack-nova-novncproxy-16.1.9~dev78-3.45.1
-
SUSE OpenStack Cloud Crowbar 8 (x86_64)
- kibana-4.6.3-3.6.1
- kibana-debuginfo-4.6.3-3.6.1
References:
- https://www.suse.com/security/cve/CVE-2016-8611.html
- https://www.suse.com/security/cve/CVE-2020-10743.html
- https://www.suse.com/security/cve/CVE-2021-3281.html
- https://bugzilla.suse.com/show_bug.cgi?id=1048688
- https://bugzilla.suse.com/show_bug.cgi?id=1164838
- https://bugzilla.suse.com/show_bug.cgi?id=1177611
- https://bugzilla.suse.com/show_bug.cgi?id=1179189
- https://bugzilla.suse.com/show_bug.cgi?id=1179955
- https://bugzilla.suse.com/show_bug.cgi?id=1180916
- https://bugzilla.suse.com/show_bug.cgi?id=1181379
- https://jira.suse.com/browse/SCRD-7737
- https://jira.suse.com/browse/SCRD-8255
- https://jira.suse.com/browse/SCRD-8294
- https://jira.suse.com/browse/SCRD-8462
- https://jira.suse.com/browse/SCRD-8705
- https://jira.suse.com/browse/SOC-10001
- https://jira.suse.com/browse/SOC-10010
- https://jira.suse.com/browse/SOC-10133
- https://jira.suse.com/browse/SOC-10150
- https://jira.suse.com/browse/SOC-10173
- https://jira.suse.com/browse/SOC-10191
- https://jira.suse.com/browse/SOC-10233
- https://jira.suse.com/browse/SOC-10288
- https://jira.suse.com/browse/SOC-10339
- https://jira.suse.com/browse/SOC-10348
- https://jira.suse.com/browse/SOC-10373
- https://jira.suse.com/browse/SOC-10378
- https://jira.suse.com/browse/SOC-10440
- https://jira.suse.com/browse/SOC-10453
- https://jira.suse.com/browse/SOC-10456
- https://jira.suse.com/browse/SOC-10549
- https://jira.suse.com/browse/SOC-10550
- https://jira.suse.com/browse/SOC-10623
- https://jira.suse.com/browse/SOC-10633
- https://jira.suse.com/browse/SOC-10636
- https://jira.suse.com/browse/SOC-10658
- https://jira.suse.com/browse/SOC-10660
- https://jira.suse.com/browse/SOC-10717
- https://jira.suse.com/browse/SOC-10740
- https://jira.suse.com/browse/SOC-10835
- https://jira.suse.com/browse/SOC-10844
- https://jira.suse.com/browse/SOC-10874
- https://jira.suse.com/browse/SOC-10877
- https://jira.suse.com/browse/SOC-10883
- https://jira.suse.com/browse/SOC-10887
- https://jira.suse.com/browse/SOC-10899
- https://jira.suse.com/browse/SOC-10952
- https://jira.suse.com/browse/SOC-11000
- https://jira.suse.com/browse/SOC-11006
- https://jira.suse.com/browse/SOC-11023
- https://jira.suse.com/browse/SOC-11028
- https://jira.suse.com/browse/SOC-11039
- https://jira.suse.com/browse/SOC-11052
- https://jira.suse.com/browse/SOC-11077
- https://jira.suse.com/browse/SOC-11079
- https://jira.suse.com/browse/SOC-11103
- https://jira.suse.com/browse/SOC-11117
- https://jira.suse.com/browse/SOC-11118
- https://jira.suse.com/browse/SOC-11119
- https://jira.suse.com/browse/SOC-11141
- https://jira.suse.com/browse/SOC-11176
- https://jira.suse.com/browse/SOC-11179
- https://jira.suse.com/browse/SOC-11190
- https://jira.suse.com/browse/SOC-11238
- https://jira.suse.com/browse/SOC-11240
- https://jira.suse.com/browse/SOC-11243
- https://jira.suse.com/browse/SOC-11248
- https://jira.suse.com/browse/SOC-11274
- https://jira.suse.com/browse/SOC-11286
- https://jira.suse.com/browse/SOC-11333
- https://jira.suse.com/browse/SOC-11429
- https://jira.suse.com/browse/SOC-5270
- https://jira.suse.com/browse/SOC-6354
- https://jira.suse.com/browse/SOC-7364
- https://jira.suse.com/browse/SOC-9288
- https://jira.suse.com/browse/SOC-9297
- https://jira.suse.com/browse/SOC-9298
- https://jira.suse.com/browse/SOC-9631
- https://jira.suse.com/browse/SOC-9632
- https://jira.suse.com/browse/SOC-9633
- https://jira.suse.com/browse/SOC-9636
- https://jira.suse.com/browse/SOC-9683
- https://jira.suse.com/browse/SOC-9695
- https://jira.suse.com/browse/SOC-9766
- https://jira.suse.com/browse/SOC-9767
- https://jira.suse.com/browse/SOC-9799
- https://jira.suse.com/browse/SOC-9849