SUSE-SU-2017:1233-1

Source
https://www.suse.com/support/update/announcement/2017/suse-su-20171233-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2017:1233-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2017:1233-1
Related
Published
2017-05-10T09:30:24Z
Modified
2025-05-02T04:05:31.741964Z
Upstream
Summary
Security update for openstack-magnum
Details

This update for openstack-magnum fixes the following issues:

Security issues fixed: - CVE-2016-7404: Magnum created instances have full API access to creating user's OpenStack account (bsc#998182).

Bugfixes: - Fixed exception for InvalidParameterValue. - Updated patches have been tested against magnum-3.1.2.dev20

References

Affected packages

SUSE:OpenStack Cloud 7 / openstack-magnum

Package

Name
openstack-magnum
Purl
pkg:rpm/suse/openstack-magnum&distro=SUSE%20OpenStack%20Cloud%207

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1.2~a0~dev20-9.4

Ecosystem specific

{
    "binaries": [
        {
            "openstack-magnum": "3.1.2~a0~dev20-9.4",
            "openstack-magnum-api": "3.1.2~a0~dev20-9.4",
            "openstack-magnum-doc": "3.1.2~a0~dev20-9.3",
            "openstack-magnum-conductor": "3.1.2~a0~dev20-9.4",
            "python-magnum": "3.1.2~a0~dev20-9.4"
        }
    ]
}

SUSE:OpenStack Cloud 7 / openstack-magnum-doc

Package

Name
openstack-magnum-doc
Purl
pkg:rpm/suse/openstack-magnum-doc&distro=SUSE%20OpenStack%20Cloud%207

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1.2~a0~dev20-9.3

Ecosystem specific

{
    "binaries": [
        {
            "openstack-magnum": "3.1.2~a0~dev20-9.4",
            "openstack-magnum-api": "3.1.2~a0~dev20-9.4",
            "openstack-magnum-doc": "3.1.2~a0~dev20-9.3",
            "openstack-magnum-conductor": "3.1.2~a0~dev20-9.4",
            "python-magnum": "3.1.2~a0~dev20-9.4"
        }
    ]
}