SUSE-SU-2022:1729-1

    Dashboard / Vulnerabilities / SUSE-SU-2022:1729-1

    SUSE-SU-2022:1729-1

    Published: 18 May 2022Last Modified: 4 Feb 2026

    Summary: Security update for ardana-barbican, grafana, openstack-barbican, openstack-cinder, openstack-heat-gbp, openstack-horizon-plugin-gbp-ui, openstack-ironic, openstack-keystone, openstack-neutron-gbp, python-lxml, release-notes-suse-openstack-cloud

    Details: This update for ardana-barbican, grafana, openstack-barbican, openstack-cinder, openstack-heat-gbp, openstack-horizon-plugin-gbp-ui, openstack-ironic, openstack-keystone, openstack-neutron-gbp, python-lxml, release-notes-suse-openstack-cloud fixes the following issues: Security fixes included on the update: ardana-barbican: - Update policies to protect container secret access (SOC-11621) - Update policies to protect secret metadata access (SOC-11620) openstack-neutron: - CVE-2021-40085: Fixed arbitrary dnsmasq reconfiguration via extra_dhcp_opts (bsc#1189794). rubygem-sinatra: - CVE-2022-29970: Fixed path traversal possible outside of public_dir when serving static files (bsc#1199138). python-XStatic-jquery-ui: - CVE-2021-41182: Fixed XSS in the `altField` option of the Datepicker widget (bsc#1192070) - CVE-2021-41183: Fixed XSS in the `of` option of the `.position()` util (bsc#1192073) - CVE-2021-41184: Fixed XSS in `*Text` options of the Datepicker widget (bsc#1192075) python-lxml: - CVE-2018-19787: Fixed that the lxml.html.clean module does remove javascript in lxml/html/clean.py (bsc#1118088). - CVE-2020-27783: Fixed mXSS due to the use of improper parser (bsc#1179534). - CVE-2021-28957: Fixed missing input sanitization for formaction HTML5 attributes that may have led to XSS (bsc#1184177). - CVE-2021-43818: Fixed HTML Cleaner that allowed crafted and SVG embedded scripts to pass through (bsc#1193752). openstack-barbican: - CVE-2022-23451: Disallows authenticated users to add/modify/delete arbitrary metadata on any secret (bsc#1194952). - CVE-2022-23452: Disallows anyone with an admin role to add their secrets to a different project's containers (bsc#1194954). grafana: - CVE-2021-44716: Fixed net/http: limit growth of header canonicalization cache (bsc#1193597). openstack-keystone: - CVE-2021-38155: Fixed information disclosure during account locking (bsc#1189390). Non-security fixes included on the update: Changes in ardana-barbican: - Update to version 9.0+git.1644879908.8a641c1: * Update policies to protect container secret access (SOC-11621) - Update to version 9.0+git.1643052417.9a3348e: * update policies to protect secret metadata access (SOC-11620) Changes in grafana: - Add CVE-2021-43813.patch (bsc#1193688, CVE-2021-43813) * directory traversal vulnerability for .md files - Bump Go to 1.16 (bsc#1193597, CVE-2021-44716) * Fix Go net/http: limit growth of header canonicalization cache Changes in openstack-barbican: - Add patches (0001-Fix-RBAC-and-ACL-access-for-managing-secret-containe.patch and 0001-Fix-policy-for-adding-a-secret-to-a-container.patch) to fix the legacy policy rules for adding a secret to a container and removing a secret from a container. bsc#1194954,CVE-2022-23452 - Add patch (0001-Fix-secret-metadata-access-rules.patch) to fix the legacy policy rules for accessing secret metadata by checking that the user making the request is authenticated for the project that owns the secret. bsc#1194952,CVE-2022-23451 Changes in openstack-cinder: - Update to version cinder-13.0.10.dev24: * Correct group:reset\_group\_snapshot\_status policy Changes in openstack-cinder: - Update to version cinder-13.0.10.dev24: * Correct group:reset\_group\_snapshot\_status policy Changes in openstack-heat-gbp: - Update to version group-based-policy-automation-14.0.1.dev4: * Add support for yoga - Update to version group-based-policy-automation-14.0.1.dev3: * Python2/3 compatibility fixes - Update to version group-based-policy-automation-14.0.1.dev2: * Add support for xena - Update to version group-based-policy-automation-14.0.1.dev1: * Remove py27 from gate jobs 14.0.0 Changes in openstack-horizon-plugin-gbp-ui: - Update to version group-based-policy-ui-14.0.1.dev3: * Add support for yoga - Update to version group-based-policy-ui-14.0.1.dev2: * Python2/3 compatibility changes - Update to version group-based-policy-ui-14.0.1.dev1: * Add support for xena 14.0.0 Changes in openstack-ironic: - Update to version ironic-11.1.5.dev18: * Cleanup stable/rocky legacy jobs Changes in openstack-ironic: - Update to version ironic-11.1.5.dev18: * Cleanup stable/rocky legacy jobs Changes in openstack-keystone: - Update to version keystone-14.2.1.dev9: * Delete system role assignments from system\_assignment table Changes in openstack-keystone: - Add patch (0001-Hide-AccountLocked-exception-from-end-users.patch) to fix the problem where AccountLocked exception discloses sensitive information. bsc#1189390,CVE-2021-38155 - Update to version keystone-14.2.1.dev9: * Delete system role assignments from system\_assignment table Changes in openstack-neutron-gbp: - Update to version group-based-policy-14.0.1.dev33: * Populate network mtu for erspan - Update to version group-based-policy-14.0.1.dev32: * ERSPAN config error when Openstack port is created in a different project than network it belongs to 2014.2.rc1 - Update to version group-based-policy-14.0.1.dev31: * Python2/3 compatibility fixes 2014.2.0rc1 - Update to version group-based-policy-14.0.1.dev29: * Fix oslo\_i18n usage - Update to version group-based-policy-14.0.1.dev27: * Update mechanism\_driver cache 2014.2.rc1 - Update to version group-based-policy-14.0.1.dev26: * Add support for xena - Update to version group-based-policy-14.0.1.dev24: * update\_floatingip\_status\_while\_deleting\_the\_vm - Update to version group-based-policy-14.0.1.dev22: * Updating host id by appending pid in existing host id 2014.2.0rc1 - Update to version group-based-policy-14.0.1.dev20: * Revert 'Add workaround to get\_subnets' Changes in python-lxml: - Fix bsc#1179534 (CVE-2020-27783) mXSS due to the use of improper parser Patch files: 0001-CVE-2020-27783.patch 0002-CVE-2020-27783.patch - Fix bsc#1118088 (CVE-2018-19787) lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, allowing a remote attacker to conduct XSS attacks Patch file: 0001-CVE-2018-19787.patch - Fix bsc#1184177 (CVE-2021-28957) missing input sanitization for formaction HTML5 attributes may lead to XSS Patch file: 0001-CVE-2021-28957.patch - Fix bsc#1193752 (CVE-2021-43818) Cleaner: Remove SVG image data URLs since they can embed script content. Reported as GHSL-2021-1037 and GHSL-2021-1038 Patch files 0001-CVE-2021-43818.patch 0002-CVE-2021-43818.patch Changes in openstack-neutron-doc: - Update to version neutron-13.0.8.dev206: * Wait longer before deleting DPDK vhu trunk bridges - Update to version neutron-13.0.8.dev205: * Do no use '--strict' for OF deletion in TRANSIENT\_TABLE - Update to version neutron-13.0.8.dev203: * Populate self.floating\_ips\_dict using 'ip rule' information - Update to version neutron-13.0.8.dev201: * [Functional] Wait for the initial state of ha router before test * Don't setup bridge controller if it is already set - Update to version neutron-13.0.8.dev198: * Remove dhcp\_extra\_opt name after first newline character - Update to version neutron-13.0.8.dev196: * [L3] Use processing queue for network update events * Add extra logs to the network update callback in L3 agent - Update to version neutron-13.0.8.dev192: * Remove dhcp\_extra\_opt value after first newline character - Update to version neutron-13.0.8.dev190: * Don't use singleton in routes.middleware.RoutesMiddleware - Update to version neutron-13.0.8.dev189: * Fix notify listener syntax for SEGMENT\_HOST\_MAPPING - Update to version neutron-13.0.8.dev188: * Clean port forwarding cache when router is DOWN - Update to version neutron-13.0.8.dev186: * Remove FIP agent's gw port when L3 agent is deleted - Update to version neutron-13.0.8.dev184: * Force to close http connection after notify about HA router status - Update to version neutron-13.0.8.dev183: * Don't configure dnsmasq entries for 'network' ports - Update to version neutron-13.0.8.dev181: * Exclude fallback tunnel devices from netns cleanup - Update to version neutron-13.0.8.dev180: * [DVR] Send allowed address pairs info to the L3 agents * designate: allow PTR zone creation to fail * Don't try to create default SG when security groups are disabled - Update to version neutron-13.0.8.dev174: * Fix update of trunk subports during live migration - Update to version neutron-13.0.8.dev172: * [ovs fw] Restrict IPv6 NA and DHCP(v6) IP and MAC source addresses - Update to version neutron-13.0.8.dev170: * Call install\_ingress\_direct\_goto\_flows() when ovs restarts - Update to version neutron-13.0.8.dev168: * Fix multicast traffic with IGMP snooping enabled - Update to version neutron-13.0.8.dev166: * Fix OVS conjunctive IP flows cleanup Changes in openstack-neutron: - Update to version neutron-13.0.8.dev206: * Wait longer before deleting DPDK vhu trunk bridges - Update to version neutron-13.0.8.dev205: * Do no use '--strict' for OF deletion in TRANSIENT\_TABLE - Update to version neutron-13.0.8.dev203: * Populate self.floating\_ips\_dict using 'ip rule' information - Update to version neutron-13.0.8.dev201: * [Functional] Wait for the initial state of ha router before test * Don't setup bridge controller if it is already set - Update to version neutron-13.0.8.dev198: * Remove dhcp\_extra\_opt name after first newline character - Update to version neutron-13.0.8.dev196: * [L3] Use processing queue for network update events * Add extra logs to the network update callback in L3 agent - Remove cve-2021-40085-stable-rocky.patch (merged upstream) - Update to version neutron-13.0.8.dev192: * Remove dhcp\_extra\_opt value after first newline character - Update to version neutron-13.0.8.dev190: * Don't use singleton in routes.middleware.RoutesMiddleware - Update to version neutron-13.0.8.dev189: * Fix notify listener syntax for SEGMENT\_HOST\_MAPPING - Add cve-2021-40085-stable-rocky.patch (bsc#1189794, CVE-2021-40085) * Remove dhcp_extra_opt value after first newline character - Update to version neutron-13.0.8.dev188: * Clean port forwarding cache when router is DOWN - Update to version neutron-13.0.8.dev186: * Remove FIP agent's gw port when L3 agent is deleted - Update to version neutron-13.0.8.dev184: * Force to close http connection after notify about HA router status - Update to version neutron-13.0.8.dev183: * Don't configure dnsmasq entries for 'network' ports - Update to version neutron-13.0.8.dev181: * Exclude fallback tunnel devices from netns cleanup - Update to version neutron-13.0.8.dev180: * [DVR] Send allowed address pairs info to the L3 agents * designate: allow PTR zone creation to fail * Don't try to create default SG when security groups are disabled - Update to version neutron-13.0.8.dev174: * Fix update of trunk subports during live migration - Update to version neutron-13.0.8.dev172: * [ovs fw] Restrict IPv6 NA and DHCP(v6) IP and MAC source addresses - Update to version neutron-13.0.8.dev170: * Call install\_ingress\_direct\_goto\_flows() when ovs restarts - Update to version neutron-13.0.8.dev168: * Fix multicast traffic with IGMP snooping enabled - Update to version neutron-13.0.8.dev166: * Fix OVS conjunctive IP flows cleanup Changes in python-Pillow: - Add 030-CVE-2022-22817.patch * From upstream, backported * Fixes CVE-2022-22817, bsc#1194521 * test from upstream updated for python2 - Add 028-CVE-2022-22815.patch * From upstream, backported * Fixes CVE-2022-22815, bsc#1194552 - Add 029-CVE-2022-22816.patch * From upstream, backported * Fixes CVE-2022-22816, bsc#1194551 Changes in python-XStatic-jquery-ui: - Update to version 1.13.0.1 (bsc#1192070, CVE-2021-41182, bsc#1192073, CVE-2021-41184, bsc#1192075, CVE-2021-41183) * Fix XSS in the altField option of the Datepicker widget (CVE-2021-41182) * Fix XSS in *Text options of the Datepicker widget (CVE-2021-41183) * Fix XSS in the of option of the .position() util (CVE-2021-41184) * Drop support for Query 1.7 * Accordion: allow function parameter for selecting header elements * Datepicker: add optional onUpdateDatepicker callback Changes in release-notes-suse-openstack-cloud: - Update to version 9.20220413: * Update release notes to indicate support for SES7 - Update to version 9.20220112: * Add reference to keystone bcrypt issue to known limitations (bsc#1186380) Changes in rubygem-sinatra: - Add CVE-2022-29970.patch (bsc#1199138, CVE-2022-29970)

    References: https://www.suse.com/support/update/announcement/2022/suse-su-20221729-1/, https://bugzilla.suse.com/1118088, https://bugzilla.suse.com/1179534, https://bugzilla.suse.com/1184177, https://bugzilla.suse.com/1186380, https://bugzilla.suse.com/1189390, https://bugzilla.suse.com/1189794, https://bugzilla.suse.com/1192070, https://bugzilla.suse.com/1192073, https://bugzilla.suse.com/1192075, https://bugzilla.suse.com/1193597, https://bugzilla.suse.com/1193688, https://bugzilla.suse.com/1193752, https://bugzilla.suse.com/1194521, https://bugzilla.suse.com/1194551, https://bugzilla.suse.com/1194552, https://bugzilla.suse.com/1194952, https://bugzilla.suse.com/1194954, https://bugzilla.suse.com/1199138, https://www.suse.com/security/cve/CVE-2018-19787, https://www.suse.com/security/cve/CVE-2020-27783, https://www.suse.com/security/cve/CVE-2021-28957, https://www.suse.com/security/cve/CVE-2021-38155, https://www.suse.com/security/cve/CVE-2021-40085, https://www.suse.com/security/cve/CVE-2021-41182, https://www.suse.com/security/cve/CVE-2021-41183, https://www.suse.com/security/cve/CVE-2021-41184, https://www.suse.com/security/cve/CVE-2021-43813, https://www.suse.com/security/cve/CVE-2021-43818, https://www.suse.com/security/cve/CVE-2021-44716, https://www.suse.com/security/cve/CVE-2022-22815, https://www.suse.com/security/cve/CVE-2022-22816, https://www.suse.com/security/cve/CVE-2022-22817, https://www.suse.com/security/cve/CVE-2022-23451, https://www.suse.com/security/cve/CVE-2022-23452, https://www.suse.com/security/cve/CVE-2022-29970

    Affected packages

    Package

    Name: ardana-barbican

    Purl: pkg:rpm/suse/ardana-barbican&distro=SUSE%20OpenStack%20Cloud%209

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -9.0+git.1644879908.8a641c1-3.13.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    SUSE-SU-2022:1729-1 | CVE-DB