SUSE-SU-2023:2378-1
Dashboard / Vulnerabilities / SUSE-SU-2023:2378-1
SUSE-SU-2023:2378-1
Summary: Security update for openstack-heat, openstack-swift, python-Werkzeug
Details: This update for openstack-heat, openstack-swift, python-Werkzeug contains the following fixes: Security fixes included in this update: openstack-heat: - CVE-2023-1625: Fixed an issue where parameter values marked as 'hidden' would be shown in the stack's environment (bsc#1209774). openstack-swift: - CVE-2022-47950: Fixed a local file disclosure that could be triggered by an authenticated attacker by supplying a malicious XML (bnc#1207035). python-Werkzeug: - CVE-2023-25577: Fixed an unbounded resource usage when parsing multipart forms with many fields (bsc#1208283). Non security changes on this update: Changes in openstack-heat: - Honor 'hidden' parameter in 'stack environment show' command. (bsc#1209774, CVE-2023-1625) Changes in openstack-swift: - Prevent XXE injections in API. (bsc#1207035, CVE-2022-47950) Changes in python-Werkzeug; - Limit maximum number of multipart form parts. (bsc#1208283, CVE-2023-25577)
References: https://www.suse.com/support/update/announcement/2023/suse-su-20232378-1/, https://bugzilla.suse.com/1207035, https://bugzilla.suse.com/1208283, https://bugzilla.suse.com/1209774, https://www.suse.com/security/cve/CVE-2022-47950, https://www.suse.com/security/cve/CVE-2023-1625, https://www.suse.com/security/cve/CVE-2023-25577
Affected packages
Package
Name: openstack-heat
Purl: pkg:rpm/suse/openstack-heat&distro=SUSE%20OpenStack%20Cloud%209
Affected ranges
Type: ECOSYSTEM
Events:
