SUSE-SU-2015:2064-1

    Dashboard / Vulnerabilities / SUSE-SU-2015:2064-1

    SUSE-SU-2015:2064-1

    Published: 20 Nov 2015Last Modified: 4 Feb 2026

    Summary: Security update for openstack-dashboard

    Details: This update provides fixes and enhancements for openstack-dashboard, crowbar-barclamp-nova_dashboard and python-django_openstack_auth. openstack-dashboard: - Reset flavors for other than 'Boot from Image' source type. (bsc#945515) - Add deactivated status for glance image. - Fix TemplateSyntaxError at hypervisors view. - Fix addition of plugin panel to panel group. - Remove admin role name 'admin' hardcode. (bsc#935442) - Escape the description param from heat template. (bsc#933722, CVE-2015-3219) - Enhance policy rules to workflow actions and identity project. - Sanitation of metadata passed from Django to avoid persistent XSS. (bsc#931437, CVE-2015-3988) - Fix Terminate Instance on network topology page. - Show ports from shared nets in floating IP assoc. - Fix incorrect ca arguments for calling ceilometer client. - Fix dynamic select layout when help block is displayed. - Pass correct project ID to get tenant_usages. (bsc#928891) crowbar-barclamp-nova_dashboard: - Allow switching on multidomain support. (bsc#945052) - Fix quoting of supported_provider_types. (bsc#936368) - Enable the POLICY_FILES setting configuration. - Fix attribute being fetched from wrong node. (bsc#936059) python-django_openstack_auth: - Remove admin role name 'admin' hardcode in User.is_superuser().

    Affected packages

    Package

    Name: crowbar-barclamp-nova_dashboard

    Purl: pkg:rpm/suse/crowbar-barclamp-nova_dashboard&distro=SUSE%20OpenStack%20Cloud%205

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.9+git.1443622531.b2b2939-9.3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    SUSE-SU-2015:2064-1 | CVE-DB