SUSE-SU-2023:2379-1
Dashboard / Vulnerabilities / SUSE-SU-2023:2379-1
SUSE-SU-2023:2379-1
Summary: Security update for openstack-heat, python-Werkzeug
Details: This update for openstack-heat, python-Werkzeug contains the following fixes: Security fixes included on this update: openstack-heat: - CVE-2023-1625: Fixed an issue where parameter values marked as 'hidden' would be shown in the stack's environment. (bsc#1209774) python-Werkzeug: - CVE-2023-25577: Fixed an unbounded resource usage when parsing multipart forms with many fields. (bsc#1208283)
References: https://www.suse.com/support/update/announcement/2023/suse-su-20232379-1/, https://bugzilla.suse.com/1208283, https://bugzilla.suse.com/1209774, https://www.suse.com/security/cve/CVE-2023-1625, https://www.suse.com/security/cve/CVE-2023-25577
Affected packages
Package
Name: openstack-heat
Purl: pkg:rpm/suse/openstack-heat&distro=HPE%20Helion%20OpenStack%208
Affected ranges
Type: ECOSYSTEM
Events:
