SUSE-SU-2023:0070-1

    Dashboard / Vulnerabilities / SUSE-SU-2023:0070-1

    SUSE-SU-2023:0070-1

    Published: 11 Jan 2023Last Modified: 4 Feb 2026

    Summary: Security update for openstack-barbican, openstack-heat-gbp, openstack-horizon-plugin-gbp-ui, openstack-neutron, openstack-neutron-gbp

    Details: This update for openstack-barbican, openstack-heat-gbp, openstack-horizon-plugin-gbp-ui, openstack-neutron, openstack-neutron-gbp fixes the following issues: Security fixes included on this update: openstack-barbican: - CVE-2022-3100: Fixed an access policy bypass via query string injection (bsc#1203873). spark: - CVE-2022-33891: Fixed a command injection vulnerability via Spark UI (bsc#1204326). Non Security fixes: Changes in openstack-barbican: - Add patch to address access policy bypass via query string injection. (bsc#1203873, CVE-2022-3100.) Changes in openstack-heat-gbp: - Update to version group-based-policy-automation-14.0.1.dev5: * Add support for zed Changes in openstack-horizon-plugin-gbp-ui: - Update to version group-based-policy-ui-14.0.1.dev6: * Add support for zed - Update to version group-based-policy-ui-14.0.1.dev5: * fix launch instance GBP issue Changes in openstack-neutron: - Update to version neutron-13.0.8.dev209: * Update documentation link for openSUSE index - Update to version neutron-13.0.8.dev208: * fix: Fix url of Floodlight - Update to version neutron-13.0.8.dev207: * Mellanox\_eth.img url expires, remove the mellanox\_eth.img node Changes in openstack-neutron: - Update to version neutron-13.0.8.dev209: * Update documentation link for openSUSE index - Update to version neutron-13.0.8.dev208: * fix: Fix url of Floodlight - Update to version neutron-13.0.8.dev207: * Mellanox\_eth.img url expires, remove the mellanox\_eth.img node Changes in openstack-neutron-gbp: - Update to version group-based-policy-14.0.1.dev52: * Fix keystone notification listener - Update to version group-based-policy-14.0.1.dev51: * Support for epg subnet 2014.2.0rc1 - Update to version group-based-policy-14.0.1.dev50: * Use top-level contract references 2014.2.rc1 - Update to version group-based-policy-14.0.1.dev48: * Remove py37 jobs from gate 2014.2rc1 Changes in spark: - Avoid using bash -c in ShellBasedGroupsMappingProvider. (bsc#1204326, CVE-2022-33891) - Add _constraints to prevent build from running out of disk space - Update to version group-based-policy-14.0.1.dev47: * Remove python39 from voting

    Affected packages

    Package

    Name: openstack-barbican

    Purl: pkg:rpm/suse/openstack-barbican&distro=SUSE%20OpenStack%20Cloud%209

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -7.0.1~dev24-3.17.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    SUSE-SU-2023:0070-1 | CVE-DB