Bugzilla – Full Text Bug Listing |
Summary: | VUL-0: CVE-2014-4615: openstack-neutron,openstack-ceilometer,python-pycadf: token leak to message queue | ||
---|---|---|---|
Product: | [Novell Products] SUSE Security Incidents | Reporter: | Johannes Segitz <jsegitz> |
Component: | Incidents | Assignee: | Security Team bot <security-team> |
Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
Severity: | Major | ||
Priority: | P3 - Medium | CC: | jsegitz, smash_bz, vuntz |
Version: | unspecified | ||
Target Milestone: | --- | ||
Hardware: | Other | ||
OS: | Other | ||
URL: | https://smash.suse.de/issue/100006/ | ||
Whiteboard: | maint:running:58796:moderate maint:released:sle11-sp3-uptu:58797 | ||
Found By: | Security Response Team | Services Priority: | |
Business Priority: | Blocker: | --- | |
Marketing QA Status: | --- | IT Deployment: | --- |
Description
Johannes Segitz
2014-06-26 11:11:57 UTC
bugbot adjusting priority (In reply to comment #0) > I have a hard time figuring out which of our products are affected. E.g. Cloud4 > uses 2014.1.1.dev1.g096106f which is older than 2014.1.1 (that's my current > understanding). I would appreciate if you could provide some insight into the > versioning of OpenStack while analyzing this bug so I can prepare the bug > report better the next time. Thanks. Taking 2014.1.1.dev1.g096106f as an example: this means that it's 2014.1.0 (which is 2014.1) + 1 commit (dev1) with the current git HEAD being 096106f. For the record, the fix in ceilometer is 2b6454f9f4e0585949ab68a91ed405755438d76e and it's in Devel:Cloud:4, but needs to be pushed for an update. The fix for neutron is in 0324965a0c2987e5cad6276f011682dec184205f. It's also in Devel:Cloud:4, and so just needs to be pushed for the update. Bernhard: since we ship python-pycadf in Cloud 4, can you also make sure it's up-to-date? We already have python-pycadf 0.5.1 everywhere. Added bnc+CVE refs to ceilometer+neutron packages submitted https://build.suse.de/request/show/43197 Cloud3 / openstack-ceilometer AFAIU this should be the only required maintenance-update because Cloud4 GM already had the other two fixes and our pycadf is newer than 0.5.0. An update workflow for this issue was started. This issue was rated as moderate. Please submit fixed packages until 2014-09-15. When done, reassign the bug to security-team@suse.de. https://swamp.suse.de/webswamp/wf/58796 Affected packages: SLE-11-SP3-PRODUCTS: openstack-ceilometer released i think... j,mm |