SUSE-SU-2018:2317-1
Vulnerability Summary
Timeline
Description
Security update for grafana, kafka, logstash, openstack-monasca-installer This update for grafana, kafka, logstash, openstack-monasca-installer fixes the following issues: Security issues fixed: - CVE-2018-12099: grafana: Fix XSS vulnerabilities in dashboard links (bsc#1096985). - CVE-2018-3817: logstash: Fix inadvertently logging of sensitive information (bsc#1090849). Bug fixes: - bsc#1095603: Disable jmxremote debugging. - bsc#1097847: Make time series database schema setup conditional. - bsc#1094448: Set log rotation options. - bsc#1090336: Add complete set of elasticsearch performance tunables. - bsc#1101366: Fix build issues with s390x, ppc64le and aarch64. - Fix various spec errors affecting Leap 15 and Tumbleweed
Affected Systems
- suse•grafana&distro=HPE Helion OpenStack 8
< 4.5.1-4.3.1
- suse•grafana&distro=SUSE OpenStack Cloud 8
< 4.5.1-4.3.1
- suse•grafana&distro=SUSE OpenStack Cloud Crowbar 8
< 4.5.1-4.3.1
- suse•kafka&distro=HPE Helion OpenStack 8
< 0.9.0.1-5.3.1
- suse•kafka&distro=SUSE OpenStack Cloud 8
< 0.9.0.1-5.3.1
- suse•kafka&distro=SUSE OpenStack Cloud Crowbar 8
< 0.9.0.1-5.3.1
- suse•logstash&distro=HPE Helion OpenStack 8
< 2.4.1-5.4.1
- suse•logstash&distro=SUSE OpenStack Cloud 8
< 2.4.1-5.4.1
- suse•logstash&distro=SUSE OpenStack Cloud Crowbar 8
< 2.4.1-5.4.1
- suse•openstack-monasca-installer&distro=HPE Helion OpenStack 8
< 20180622_15.06-3.6.1
- suse•openstack-monasca-installer&distro=SUSE OpenStack Cloud 8
< 20180622_15.06-3.6.1
- suse•openstack-monasca-installer&distro=SUSE OpenStack Cloud Crowbar 8
< 20180622_15.06-3.6.1
References (10)
- https://www.suse.com/support/update/announcement/2018/suse-su-20182317-1/
- https://bugzilla.suse.com/1090336
- https://bugzilla.suse.com/1090849
- https://bugzilla.suse.com/1094448
- https://bugzilla.suse.com/1095603
- https://bugzilla.suse.com/1096985
- https://bugzilla.suse.com/1097847
- https://bugzilla.suse.com/1101366
- https://www.suse.com/security/cve/CVE-2018-12099
- https://www.suse.com/security/cve/CVE-2018-3817