-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat Enterprise Linux OpenStack Platform security update Advisory ID: RHSA-2018:2729-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2018:2729 Issue date: 2018-09-19 Cross references: RHSA-2018:2439 RHSA-2018:2482 RHSA-2018:2557 CVE Names: CVE-2017-3636 CVE-2017-3641 CVE-2017-3651 CVE-2017-3653 CVE-2017-10268 CVE-2017-10378 CVE-2017-10379 CVE-2017-10384 CVE-2018-2562 CVE-2018-2622 CVE-2018-2640 CVE-2018-2665 CVE-2018-2668 CVE-2018-2755 CVE-2018-2761 CVE-2018-2767 CVE-2018-2771 CVE-2018-2781 CVE-2018-2813 CVE-2018-2817 CVE-2018-2819 CVE-2018-10892 CVE-2018-10915 CVE-2018-14620 ==================================================================== 1. Summary: An update is now available for Red Hat OpenStack Platform 12.0 (Pike). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat OpenStack Platform provides the facilities for building, deploying and monitoring a private or public infrastructure-as-a-service (IaaS) cloud running on commonly available physical hardware. Security Fix(es): * openstack-rabbitmq-container: Insecure download of rabbitmq_clusterer during docker build (CVE-2018-14620) For more details about the security issue, including the impact, a CVSS score, and other related information, refer to the CVE page listed in the References section. The Red Hat OpenStack Platform container images have been updated to address security advisory/ies: RHSA-2018:2439, RHSA-2018:2482, RHSA-2018:2557. 3. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing this update, the MariaDB server daemon (mysqld) will be restarted automatically. 4. Bugs fixed (https://bugzilla.redhat.com/): 1626953 - CVE-2018-14620 openstack-rabbitmq-container: Insecure download of rabbitmq_clusterer during docker build 5. References: https://access.redhat.com/security/cve/CVE-2017-3636 https://access.redhat.com/security/cve/CVE-2017-3641 https://access.redhat.com/security/cve/CVE-2017-3651 https://access.redhat.com/security/cve/CVE-2017-3653 https://access.redhat.com/security/cve/CVE-2017-10268 https://access.redhat.com/security/cve/CVE-2017-10378 https://access.redhat.com/security/cve/CVE-2017-10379 https://access.redhat.com/security/cve/CVE-2017-10384 https://access.redhat.com/security/cve/CVE-2018-2562 https://access.redhat.com/security/cve/CVE-2018-2622 https://access.redhat.com/security/cve/CVE-2018-2640 https://access.redhat.com/security/cve/CVE-2018-2665 https://access.redhat.com/security/cve/CVE-2018-2668 https://access.redhat.com/security/cve/CVE-2018-2755 https://access.redhat.com/security/cve/CVE-2018-2761 https://access.redhat.com/security/cve/CVE-2018-2767 https://access.redhat.com/security/cve/CVE-2018-2771 https://access.redhat.com/security/cve/CVE-2018-2781 https://access.redhat.com/security/cve/CVE-2018-2813 https://access.redhat.com/security/cve/CVE-2018-2817 https://access.redhat.com/security/cve/CVE-2018-2819 https://access.redhat.com/security/cve/CVE-2018-10892 https://access.redhat.com/security/cve/CVE-2018-10915 https://access.redhat.com/security/cve/CVE-2018-14620 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/security/cve/CVE-2018-14620 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2018 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBW6OAjNzjgjWX9erEAQjW9g//b6m07yIvZB6dZFDvgZAws3nFRNMyPiq0 v46z32zNN7b4QGxVe4F1x1uNkScIME8PCTPkZFRyioFGCbu42Co5zWIava0YdEhJ 0Vm3BXOSUmt5nFFvNqB6SvbTMBcuCn98vZ31X6t55sXylHSzEkL6Jjn0zEVYTwWw Jr5ahY5fPClFbvcMEBQ/MKGgS840VzcEzx7ScLuNtKaUL5bSC2zGJbKeu+qekIzH QxY1j9BmjxcJ9AAJCu1zieJjTbdVdQ8pohBpJDtpe33al8GK1csE4wZAfy2oKaXl dSJlkdgYRkH/1jXjqj1T7CiPr3S8L/VwCm8NcIDImbbDpZ1yzF6Obyf+qs2RTO50 LignXhZ9rl3zSnVEXWbyI0IdQjLXbBLlwZxtTcQ+7BXx8uItUOFSxFz/Gt91FF2p lT6gvD5KQ5f8uTZH9Wq0xAd6fDmvhYwTJklnQ0gTehFPyAnOuheSCH7qVkoQrUtO nnQz+/EY9wX7fxPxs2YS2SkWjmgI1rp0wpIHqgd+aK52rltVxlCMCR6LaA/deJiw J8Uu61gszCElPLw3W4DKCmeKBP7sD7ZcmIwJTq2bpaum5Ym/RkH68sFYP6sfvcQ2 y3QCguwMPTNJ/ieottjGCAd8+zO1vCcWRy4KF9LTPXRm3rnds1ibjJnei5AhrqVJ +lkQ5BUzhs4=cP2C -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce