[SRU] queens stable releases
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Ubuntu Cloud Archive |
Invalid
|
Undecided
|
Unassigned | ||
Queens |
Fix Released
|
High
|
Unassigned | ||
cinder (Ubuntu) |
Invalid
|
Undecided
|
Unassigned | ||
Bionic |
Fix Released
|
High
|
Unassigned | ||
horizon (Ubuntu) |
Invalid
|
Undecided
|
Unassigned | ||
Bionic |
Fix Released
|
High
|
Unassigned | ||
keystone (Ubuntu) |
Invalid
|
Undecided
|
Unassigned | ||
Bionic |
Fix Released
|
High
|
Unassigned | ||
neutron (Ubuntu) |
Invalid
|
Undecided
|
Unassigned | ||
Bionic |
Fix Released
|
High
|
Unassigned | ||
neutron-fwaas (Ubuntu) |
Invalid
|
Undecided
|
Unassigned | ||
Bionic |
Fix Released
|
High
|
Unassigned | ||
nova (Ubuntu) |
Invalid
|
Undecided
|
Unassigned | ||
Bionic |
Fix Released
|
High
|
Unassigned |
Bug Description
[Impact]
This release sports mostly bug-fixes and we would like to make sure all of our supported customers have access to these improvements. The update contains the following package updates:
cinder 12.0.10
keystone 13.0.4
horizon 13.0.3
neutron 12.1.1
neutron-fwaas 12.0.2
nova 17.0.13
[Test Case]
The following SRU process was followed:
https:/
In order to avoid regression of existing consumers, the OpenStack team will run their continuous integration test against the packages that are in -proposed. A successful run of all available tests will be required before the proposed packages can be let into -updates.
The OpenStack team will be in charge of attaching the output summary of the executed tests. The OpenStack team members will not mark ‘verification-done’ until this has happened.
[Regression Potential]
In order to mitigate the regression potential, the results of the
aforementioned tests are attached to this bug.
[Discussion]
keystone 13.0.4 will be going through the security team as it includes security fixes.
CVE References
Changed in cloud-archive: | |
status: | New → Invalid |
Changed in keystone (Ubuntu Bionic): | |
status: | New → Triaged |
importance: | Undecided → High |
Changed in keystone (Ubuntu): | |
status: | New → Invalid |
description: | updated |
Changed in cinder (Ubuntu): | |
status: | New → Invalid |
Changed in horizon (Ubuntu): | |
status: | New → Invalid |
Changed in neutron (Ubuntu): | |
status: | New → Invalid |
Changed in neutron-fwaas (Ubuntu): | |
status: | New → Invalid |
Changed in nova (Ubuntu): | |
status: | New → Invalid |
importance: | Undecided → High |
status: | Invalid → Triaged |
Changed in neutron-fwaas (Ubuntu): | |
importance: | Undecided → High |
status: | Invalid → Triaged |
Changed in neutron (Ubuntu): | |
importance: | Undecided → High |
status: | Invalid → Triaged |
Changed in horizon (Ubuntu): | |
importance: | Undecided → High |
status: | Invalid → Triaged |
Changed in cinder (Ubuntu): | |
importance: | Undecided → High |
status: | Invalid → Triaged |
Changed in neutron (Ubuntu Bionic): | |
importance: | Undecided → High |
status: | New → Triaged |
Changed in neutron-fwaas (Ubuntu Bionic): | |
importance: | Undecided → High |
status: | New → Triaged |
Changed in nova (Ubuntu Bionic): | |
importance: | Undecided → High |
status: | New → Triaged |
Changed in cinder (Ubuntu Bionic): | |
importance: | Undecided → High |
status: | New → Triaged |
Changed in neutron (Ubuntu): | |
importance: | High → Undecided |
status: | Triaged → Invalid |
Changed in neutron-fwaas (Ubuntu): | |
importance: | High → Undecided |
status: | Triaged → Invalid |
Changed in nova (Ubuntu): | |
importance: | High → Undecided |
status: | Triaged → Invalid |
Changed in cinder (Ubuntu): | |
importance: | High → Undecided |
status: | Triaged → Invalid |
Changed in glance (Ubuntu): | |
status: | New → Invalid |
Changed in horizon (Ubuntu): | |
importance: | High → Undecided |
status: | Triaged → Invalid |
Changed in glance (Ubuntu Bionic): | |
importance: | Undecided → High |
status: | New → Triaged |
Changed in horizon (Ubuntu Bionic): | |
importance: | Undecided → High |
status: | New → Triaged |
description: | updated |
no longer affects: | glance (Ubuntu) |
no longer affects: | glance (Ubuntu Bionic) |
tags: |
added: verification-done verification-done-bionic removed: verification-needed verification-needed-bionic |
This bug was fixed in the package keystone - 2:13.0.4-0ubuntu1
---------------
keystone (2:13.0.4-0ubuntu1) bionic-security; urgency=medium
[ Chris MacNaughton ] fixing- dn-to-id. patch: Dropped. Fixed in upstream
* d/watch: Update to point at opendev.org.
* New stable point release for OpenStack Queens (LP: #1893234).
- d/p/0001-
release.
[ Corey Bryant ] patches/ CVE-2020- 12689-CVE- 2020-12691. patch: Fix security patches/ CVE-2020- 12690.patch: Ensure OAuth1 authorized patches/ CVE-2020- 12692.patch: Check timestamp of signed
* SECURITY UPDATE: EC2 and/or credential endpoints are not protected
from a scoped context. Keystone V3 /credentials endpoint policy
logic allows to change credentials owner or target project ID.
- debian/
issues with EC2 credentials, addressing several issues in the
creation and use of EC2/S3 credentials with keystone tokens.
- CVE-2020-12689, CVE-2020-12691
* SECURITY UPDATE: OAuth1 request token authorize silently ignores
roles parameter.
- debian/
roles are respected.
- CVE-2020-12691
* SECURITY UPDATE: Keystone doesn't check signature TTL of the EC2
credential auth method.
- debian/
EC2 token request.
- CVE-2020-12692
-- Corey Bryant <email address hidden> Fri, 28 Aug 2020 09:29:34 -0400