SUSE-SU-2017:2627-1
Dashboard / Vulnerabilities / SUSE-SU-2017:2627-1
SUSE-SU-2017:2627-1
Summary: Security update for openstack-aodh
Details: This update for openstack-aodh fixes the following security issues: - CVE-2017-12440: Aodh did not verify that trust IDs belong to the user when creating alarm action with the scheme trust+http, which allowed remote authenticated users with knowledge of trust IDs where Aodh is the trustee to obtain a Keystone token and perform unspecified authenticated actions by adding an alarm action with the scheme trust+http, and providing a trust id where Aodh is the trustee (bsc#1052604). - gnocchi: Fix alarms for unprivileged user.
References: https://www.suse.com/support/update/announcement/2017/suse-su-20172627-1/, https://bugzilla.suse.com/1052604, https://www.suse.com/security/cve/CVE-2017-12440
Affected packages
Package
Name: openstack-aodh
Purl: pkg:rpm/suse/openstack-aodh&distro=SUSE%20OpenStack%20Cloud%207
Affected ranges
Type: ECOSYSTEM
Events:
