SUSE-SU-2019:2049-1
Dashboard / Vulnerabilities / SUSE-SU-2019:2049-1
SUSE-SU-2019:2049-1
Summary: Security update for ceph
Details: This update for ceph fixes the following issues: Security issues fixed: - CVE-2019-3821: civetweb: fix file descriptor leak (bsc#1125080) - CVE-2018-16889: rgw: sanitize customer encryption keys from log output in v4 auth (bsc#1121567) Non-security issues fixed: - install grafana dashboards world readable (bsc#1136110) - upgrade results in cluster outage (bsc#1132396) - ceph status reports 'HEALTH_WARN 3 monitors have not enabled msgr2' (bsc#1124957) - Dashboard: Opening tcmu-runner perf counters results in a 404 (bsc#1135388) - RadosGW stopped expiring objects (bsc#1133139) - Ceph does not recover when rebuilding every OSD (bsc#1133461)
References: https://www.suse.com/support/update/announcement/2019/suse-su-20192049-1/, https://bugzilla.suse.com/1121567, https://bugzilla.suse.com/1123360, https://bugzilla.suse.com/1124957, https://bugzilla.suse.com/1125080, https://bugzilla.suse.com/1125899, https://bugzilla.suse.com/1131984, https://bugzilla.suse.com/1132396, https://bugzilla.suse.com/1133139, https://bugzilla.suse.com/1133461, https://bugzilla.suse.com/1135030, https://bugzilla.suse.com/1135219, https://bugzilla.suse.com/1135221, https://bugzilla.suse.com/1135388, https://bugzilla.suse.com/1136110, https://www.suse.com/security/cve/CVE-2018-16889, https://www.suse.com/security/cve/CVE-2019-3821
Affected packages
Package
Name: ceph
Purl: pkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1
Affected ranges
Type: ECOSYSTEM
Events:
