SUSE-SU-2019:0499-1
Dashboard / Vulnerabilities / SUSE-SU-2019:0499-1
SUSE-SU-2019:0499-1
Summary: Security update for ceph
Details: This update for ceph fixes the following issues: Security issues fixed: - CVE-2018-14662: mon: limit caps allowed to access the config store (bsc#1111177) - CVE-2018-16846: rgw: enforce bounds on max-keys/max-uploads/max-parts (bsc#1114710) - CVE-2018-16889: rgw: sanitize customer encryption keys from log output in v4 auth (bsc#1121567) Non-security issue fixed: - os/bluestore: avoid frequent allocator dump on bluefs rebalance failure (bsc#1113246)
References: https://www.suse.com/support/update/announcement/2019/suse-su-20190499-1/, https://bugzilla.suse.com/1111177, https://bugzilla.suse.com/1113246, https://bugzilla.suse.com/1114710, https://bugzilla.suse.com/1121567, https://www.suse.com/security/cve/CVE-2018-14662, https://www.suse.com/security/cve/CVE-2018-16846, https://www.suse.com/security/cve/CVE-2018-16889
Affected packages
Package
Name: ceph
Purl: pkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
