{"schema_version":"1.7.3","id":"SUSE-SU-2020:3624-1","published":"2020-12-04T11:50:23Z","modified":"2025-05-02T04:10:02.691016Z","related":["CVE-2016-8611","CVE-2019-20933","CVE-2019-9740","CVE-2020-24303","CVE-2020-26137"],"upstream":["CVE-2016-8611","CVE-2019-20933","CVE-2019-9740","CVE-2020-24303","CVE-2020-26137"],"summary":"Security update for crowbar-openstack, grafana, influxdb, python-urllib3","details":"This update for crowbar-openstack, grafana, influxdb, python-urllib3 contains the following fixes:\n\nSecurity fixes included in this update:\n\nopenstack-glance\n- CVE-2016-8611: Added rate limiting for glance api (bnc#1005886)\n\ngrafana\n- CVE-2020-24303: Fixed an XSS via a query alias for the ElasticSearch datasource (#bnc#1178243)\n\ninfluxdb\n- CVE-2019-20933: Fixed an authentication bypass (bnc#1178988)\n\npython-urlib3\n- CVE-2019-9740: Fixed a CRLF injection in urllib3 (bnc#1129071).\n- CVE-2020-26137: Fixed a CRLF injection via HTTP request method (bnc#1177120)\n\nmemcached\n- CVE-2018-1000115: Fixed a issue where a UDP server allowed spoofed traffic amplification DoS (bnc#1083903).\n\nNon-security fixes included in this update:\n\nChanges in crowbar-openstack:\n- Update to version 4.0+git.1604938545.30c10db18:\n  * rabbitmq: Fix crm running check (SOC-11240)\n\nChanges in grafana:\n- Fix bnc#1178243 CVE-2020-24303 by adding\n  25401-Fix-XSS-vulnerability-with-series-overrides.patch\n\nChanges in influxdb:\n- Add CVE-2019-20933.patch (bnc#1178988, CVE-2019-20933) to\n  fix authentication bypass_\n- Declare license files correctly\n\n- Version 1.2.4:\n  * The stress tool influx_stress will be removed in a subsequent\n    release.\n  * Remove the override of GOMAXPROCS.\n  * Uncomment section headers from the default configuration file.\n  * Improve write performance significantly.\n  * Prune data in meta store for deleted shards.\n  * Update latest dependencies with Godeps.\n  * Introduce syntax for marking a partial response with chunking.\n  * Use X-Forwarded-For IP address in HTTP logger if present.\n  * Add support for secure transmission via collectd.\n  * Switch logging to use structured logging everywhere.\n  * [CLI feature request] USE retention policy for queries.\n  * Add clear command to cli.\n  * Adding ability to use parameters in queries in the v2 client\n    using the Parameters map in the Query struct.\n  * Allow add items to array config via ENV\n  * Support subquery execution in the query language.\n  * Verbose output for SSL connection errors.\n  * Cache snapshotting performance improvements\n\n- Partially revert previous change to fix build for Leap\n\nChanges in python-urllib3:\n- Update urllib3-fix-test-urls.patch. Adjust to match upstream solution.\n\n- Add urllib3-fix-test-urls.patch. Fix tests failing on python checks for\n  CVE-2019-9740.\n\n- Add urllib3-cve-2020-26137.patch. Don't allow control chars in request\n  method. (bnc#1177120, CVE-2020-26137)\n\n  ","affected":[{"package":{"name":"crowbar-openstack","ecosystem":"SUSE:OpenStack Cloud 7","purl":"pkg:rpm/suse/crowbar-openstack&distro=SUSE%20OpenStack%20Cloud%207"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.0+git.1604938545.30c10db18-9.77.1"}]}],"ecosystem_specific":{"binaries":[{"crowbar-openstack":"4.0+git.1604938545.30c10db18-9.77.1","grafana":"6.7.4-1.20.1","influxdb":"1.2.4-5.1","python-urllib3":"1.16-3.12.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:3624-1.json"}},{"package":{"name":"grafana","ecosystem":"SUSE:OpenStack Cloud 7","purl":"pkg:rpm/suse/grafana&distro=SUSE%20OpenStack%20Cloud%207"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.7.4-1.20.1"}]}],"ecosystem_specific":{"binaries":[{"crowbar-openstack":"4.0+git.1604938545.30c10db18-9.77.1","grafana":"6.7.4-1.20.1","influxdb":"1.2.4-5.1","python-urllib3":"1.16-3.12.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:3624-1.json"}},{"package":{"name":"influxdb","ecosystem":"SUSE:OpenStack Cloud 7","purl":"pkg:rpm/suse/influxdb&distro=SUSE%20OpenStack%20Cloud%207"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.4-5.1"}]}],"ecosystem_specific":{"binaries":[{"crowbar-openstack":"4.0+git.1604938545.30c10db18-9.77.1","grafana":"6.7.4-1.20.1","influxdb":"1.2.4-5.1","python-urllib3":"1.16-3.12.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:3624-1.json"}},{"package":{"name":"python-urllib3","ecosystem":"SUSE:OpenStack Cloud 7","purl":"pkg:rpm/suse/python-urllib3&distro=SUSE%20OpenStack%20Cloud%207"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.16-3.12.1"}]}],"ecosystem_specific":{"binaries":[{"crowbar-openstack":"4.0+git.1604938545.30c10db18-9.77.1","grafana":"6.7.4-1.20.1","influxdb":"1.2.4-5.1","python-urllib3":"1.16-3.12.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:3624-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2020/suse-su-20203624-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1005886"},{"type":"REPORT","url":"https://bugzilla.suse.com/1170479"},{"type":"REPORT","url":"https://bugzilla.suse.com/1177120"},{"type":"REPORT","url":"https://bugzilla.suse.com/1178243"},{"type":"REPORT","url":"https://bugzilla.suse.com/1178988"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-8611"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-20933"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-9740"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-24303"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-26137"}]}