SUSE-SU-2023:0070-1
Dashboard / Vulnerabilities / SUSE-SU-2023:0070-1
SUSE-SU-2023:0070-1
Summary: Security update for openstack-barbican, openstack-heat-gbp, openstack-horizon-plugin-gbp-ui, openstack-neutron, openstack-neutron-gbp
Details: This update for openstack-barbican, openstack-heat-gbp, openstack-horizon-plugin-gbp-ui, openstack-neutron, openstack-neutron-gbp fixes the following issues: Security fixes included on this update: openstack-barbican: - CVE-2022-3100: Fixed an access policy bypass via query string injection (bsc#1203873). spark: - CVE-2022-33891: Fixed a command injection vulnerability via Spark UI (bsc#1204326). Non Security fixes: Changes in openstack-barbican: - Add patch to address access policy bypass via query string injection. (bsc#1203873, CVE-2022-3100.) Changes in openstack-heat-gbp: - Update to version group-based-policy-automation-14.0.1.dev5: * Add support for zed Changes in openstack-horizon-plugin-gbp-ui: - Update to version group-based-policy-ui-14.0.1.dev6: * Add support for zed - Update to version group-based-policy-ui-14.0.1.dev5: * fix launch instance GBP issue Changes in openstack-neutron: - Update to version neutron-13.0.8.dev209: * Update documentation link for openSUSE index - Update to version neutron-13.0.8.dev208: * fix: Fix url of Floodlight - Update to version neutron-13.0.8.dev207: * Mellanox\_eth.img url expires, remove the mellanox\_eth.img node Changes in openstack-neutron: - Update to version neutron-13.0.8.dev209: * Update documentation link for openSUSE index - Update to version neutron-13.0.8.dev208: * fix: Fix url of Floodlight - Update to version neutron-13.0.8.dev207: * Mellanox\_eth.img url expires, remove the mellanox\_eth.img node Changes in openstack-neutron-gbp: - Update to version group-based-policy-14.0.1.dev52: * Fix keystone notification listener - Update to version group-based-policy-14.0.1.dev51: * Support for epg subnet 2014.2.0rc1 - Update to version group-based-policy-14.0.1.dev50: * Use top-level contract references 2014.2.rc1 - Update to version group-based-policy-14.0.1.dev48: * Remove py37 jobs from gate 2014.2rc1 Changes in spark: - Avoid using bash -c in ShellBasedGroupsMappingProvider. (bsc#1204326, CVE-2022-33891) - Add _constraints to prevent build from running out of disk space - Update to version group-based-policy-14.0.1.dev47: * Remove python39 from voting
References: https://www.suse.com/support/update/announcement/2023/suse-su-20230070-1/, https://bugzilla.suse.com/1203873, https://bugzilla.suse.com/1204326, https://www.suse.com/security/cve/CVE-2022-3100, https://www.suse.com/security/cve/CVE-2022-33891
Affected packages
Package
Name: openstack-barbican
Purl: pkg:rpm/suse/openstack-barbican&distro=SUSE%20OpenStack%20Cloud%209
Affected ranges
Type: ECOSYSTEM
Events:
