SUSE-SU-2015:2064-1
Dashboard / Vulnerabilities / SUSE-SU-2015:2064-1
SUSE-SU-2015:2064-1
Summary: Security update for openstack-dashboard
Details: This update provides fixes and enhancements for openstack-dashboard, crowbar-barclamp-nova_dashboard and python-django_openstack_auth. openstack-dashboard: - Reset flavors for other than 'Boot from Image' source type. (bsc#945515) - Add deactivated status for glance image. - Fix TemplateSyntaxError at hypervisors view. - Fix addition of plugin panel to panel group. - Remove admin role name 'admin' hardcode. (bsc#935442) - Escape the description param from heat template. (bsc#933722, CVE-2015-3219) - Enhance policy rules to workflow actions and identity project. - Sanitation of metadata passed from Django to avoid persistent XSS. (bsc#931437, CVE-2015-3988) - Fix Terminate Instance on network topology page. - Show ports from shared nets in floating IP assoc. - Fix incorrect ca arguments for calling ceilometer client. - Fix dynamic select layout when help block is displayed. - Pass correct project ID to get tenant_usages. (bsc#928891) crowbar-barclamp-nova_dashboard: - Allow switching on multidomain support. (bsc#945052) - Fix quoting of supported_provider_types. (bsc#936368) - Enable the POLICY_FILES setting configuration. - Fix attribute being fetched from wrong node. (bsc#936059) python-django_openstack_auth: - Remove admin role name 'admin' hardcode in User.is_superuser().
References: https://www.suse.com/support/update/announcement/2015/suse-su-20152064-1/, https://bugzilla.suse.com/928891, https://bugzilla.suse.com/931437, https://bugzilla.suse.com/933607, https://bugzilla.suse.com/933722, https://bugzilla.suse.com/935442, https://bugzilla.suse.com/936059, https://bugzilla.suse.com/936368, https://bugzilla.suse.com/945052, https://bugzilla.suse.com/945515, https://www.suse.com/security/cve/CVE-2015-3219, https://www.suse.com/security/cve/CVE-2015-3988
Affected packages
Package
Name: crowbar-barclamp-nova_dashboard
Purl: pkg:rpm/suse/crowbar-barclamp-nova_dashboard&distro=SUSE%20OpenStack%20Cloud%205
Affected ranges
Type: ECOSYSTEM
Events:
