{"id":22105,"date":"2022-03-24T19:30:02","date_gmt":"2022-03-24T15:30:02","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/166443\/RHSA-2022-0995-01.txt"},"modified":"2022-03-28T09:41:42","modified_gmt":"2022-03-28T05:11:42","slug":"red-hat-security-advisory-2022-0995-01","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/red-hat-security-advisory-2022-0995-01\/","title":{"rendered":"Red Hat Security Advisory 2022-0995-01"},"content":{"rendered":"<p dir=\"ltr\">&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>\nHash: SHA256<\/p>\n<p dir=\"ltr\">=====================================================================<br \/>\nRed Hat Security Advisory<\/p>\n<p dir=\"ltr\">Synopsis: Moderate: Red Hat OpenStack Platform 16.2 (openstack-tripleo-heat-templates) security update<br \/>\nAdvisory ID: RHSA-2022:0995-01<br \/>\nProduct: Red Hat OpenStack Platform<br \/>\nAdvisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2022:0995<br \/>\nIssue date: 2022-03-23<br \/>\nCVE Names: CVE-2021-4180<br \/>\n=====================================================================<\/p>\n<p dir=\"ltr\">1. Summary:<\/p>\n<p dir=\"ltr\">An update for openstack-tripleo-heat-templates is now available for Red Hat<br \/>\nOpenStack Platform 16.2 (Train).<\/p>\n<p dir=\"ltr\">Red Hat Product Security has rated this update as having a security impact<br \/>\nof Moderate. A Common Vulnerability Scoring System (CVSS) base score, which<br \/>\ngives a detailed severity rating, is available for each vulnerability from<br \/>\nthe CVE link(s) in the References section.<\/p>\n<p dir=\"ltr\">2. Relevant releases\/architectures:<\/p>\n<p dir=\"ltr\">Red Hat OpenStack Platform 16.2 &#8211; noarch<\/p>\n<p dir=\"ltr\">3. Description:<\/p>\n<p dir=\"ltr\">Heat templates for TripleO<\/p>\n<p dir=\"ltr\">Security Fix(es):<\/p>\n<p dir=\"ltr\">* Data leak of internal URL through keystone_authtoken (CVE-2021-4180)<\/p>\n<p dir=\"ltr\">For more details about the security issue(s), including the impact, a CVSS<br \/>\nscore, acknowledgments, and other related information, refer to the CVE<br \/>\npage listed in the References section.<\/p>\n<p dir=\"ltr\">4. Solution:<\/p>\n<p dir=\"ltr\">For details on how to apply this update, which includes the changes<br \/>\ndescribed in this advisory, refer to:<\/p>\n<p dir=\"ltr\">https:\/\/access.redhat.com\/articles\/11258<\/p>\n<p dir=\"ltr\">5. Bugs fixed (https:\/\/bugzilla.redhat.com\/):<\/p>\n<p dir=\"ltr\">1855678 &#8211; Configure Ceph Messenger for encryption OTW<br \/>\n1869587 &#8211; Octavia and LB issues after OSP13z11 and OSP16.x upgrade<br \/>\n1886762 &#8211; [RFE] support NFS mount at the conversion directory<br \/>\n1921112 &#8211; [OSP13-&gt;OSP16.2] nova-consoleauth still present in cli after upgrade.<br \/>\n1949673 &#8211; [RHOSP16.2] [rsyslog] Miss configuration generated in 50_openstack_logs.conf<br \/>\n1949675 &#8211; [RHOSP16.2] [rsyslog] rsyslog containers does not forward logs to elasticsearch<br \/>\n1955562 &#8211; Backup and Restore: Backup openstack client integration &#8211; openstack backup using bad nfs server address is not erroring out<br \/>\n1962304 &#8211; cinder volume at DCN unable to read central cephx keyring<br \/>\n1965233 &#8211; [FFU 13 -&gt; 16.x] xinetd is running after upgrade, blocking swift_rsync container<br \/>\n1969411 &#8211; [RFE]: allow for the deployment of RHCS dashboard on any composable network<br \/>\n1975271 &#8211; Minor update does not restart ha resource when it is in failed stated<br \/>\n1976055 &#8211; Configuration of Memcached TLS requires the user to duplicate configuration entries<br \/>\n1978228 &#8211; [OSP13-&gt;OSP16.2] Leapp upgrade failed with TLSEverywhere<br \/>\n1980542 &#8211; [16.2] LC_CTYPE: cannot change locale (C.UTF-8) during OC upgrade 13 to 16.2 seems to fail upgrade<br \/>\n1983748 &#8211; NeutronL3AgentAvailabilityZone does not set specified value for Availability zone of Neutron L3 agent<br \/>\n1984555 &#8211; [RHOSP16.2] Smart plugin doesn&#8217;t work for CAP_SYS_RAWIO capability missing.<br \/>\n1984875 &#8211; [OSP13-&gt;16.2] the leapp persistentnetnamesdisable actor should be removed so that a reboot can be avoided<br \/>\n1992506 &#8211; [RHOSP16.2] dpdk ovs vhost postcopy requires to start ovs with &#8211;mlockall=no<br \/>\n1999324 &#8211; NovaLiveMigrationPermitAutoConverge should default to true to match NovaLiveMigrationPermitPostCopy<br \/>\n1999725 &#8211; [RFE] Allow for the deployment of Ganesha on the overcloud &#8220;external&#8221; network<br \/>\n2000582 &#8211; ceph ssl radosgw port is closed for tempest (undercloud node)<br \/>\n2002346 &#8211; [OSP-16.2] [Upgrades][TripleO] Revert of the TSX change in tripleoclient<br \/>\n2003176 &#8211; [OSP16.2] ovn-dbs pacemaker update_tasks can race with pacemaker update_tasks<br \/>\n2005086 &#8211; Unable to disable gateway validation on deployment<br \/>\n2005680 &#8211; Cinder __DEFAULT__ volume type is installed but *tripleo* volume type is the real default<br \/>\n2008418 &#8211; Stack reconfiguration failed because ha-proxy container crashed during reconfiguration<br \/>\n2009422 &#8211; Deployment failing due to &#8220;Create \/etc\/openstack directory if it does not exist&#8221; task<br \/>\n2010114 &#8211; Openstack ceilometer archival policy is not taking effect<br \/>\n2010703 &#8211; rhosp-release package is removed during upgrade from all nodes<br \/>\n2010940 &#8211; ceph-nfs not coming up after the FFU<br \/>\n2013913 &#8211; Minion should be configured with same default tuning as Undercloud for atleast heat &amp; ironic<br \/>\n2014758 &#8211; There&#8217;s a typo in MySQLInodbBufferPoolSize as it should be MySQLInnodbBufferPoolSize<br \/>\n2021575 &#8211; [16.2] openstack overcloud upgrade run times out \/ HAProxy container fails to start<br \/>\n2022234 &#8211; Parameter &#8216;ValidateGatewaysIcmp:false&#8217; is not working in OSP16.2<br \/>\n2022691 &#8211; [OSP16.2] qemu logs are not accessible on the host<br \/>\n2026290 &#8211; Some log files are not collected\/relayed by rsyslog to remote log server<br \/>\n2027787 &#8211; Undercloud upgrade to 16.2 fails because of missing dependencies of swtpm<br \/>\n2030409 &#8211; [OSP16.2] Memcached if off for Heat, Keystone and Nova since caching backend is dogpile.cache.null<br \/>\n2031110 &#8211; Long t-h-t role name causes OVNMacAddressPort tag to exceed the neutron tag length limit<br \/>\n2032010 &#8211; [OSP16.2.0] neutron-dhcp-agent causes oom issues on controllers<br \/>\n2034189 &#8211; Validation if NTP\/Chrony is configured during at initial stage of deployment procedure<br \/>\n2034730 &#8211; Horizon log not collected\/relayed by rsyslog to remote log server<br \/>\n2035793 &#8211; CVE-2021-4180 openstack-tripleo-heat-templates: data leak of internal URL through keystone_authtoken<br \/>\n2037940 &#8211; [OVN] Enable ovn-monitor-all to help with OVN scale<br \/>\n2038897 &#8211; [RHOSP16.2] [DCN] [STF] metrics_qdr containers failed to start with bind address error<br \/>\n2046185 &#8211; From time to time memcached stops processing requests and brings down OpenStack control plane<br \/>\n2046211 &#8211; [OSP13-&gt;OSP16.2] Leapp actors directory change impacting in the upgrade<br \/>\n2050154 &#8211; [update] 16.1-&gt;16.2 experience a connectivity cut (ping loss) to FIP during update of the controllers.<\/p>\n<p dir=\"ltr\">6. Package List:<\/p>\n<p dir=\"ltr\">Red Hat OpenStack Platform 16.2:<\/p>\n<p dir=\"ltr\">Source:<br \/>\nopenstack-tripleo-heat-templates-11.6.1-2.20220116004912.el8ost.src.rpm<\/p>\n<p dir=\"ltr\">noarch:<br \/>\nopenstack-tripleo-heat-templates-11.6.1-2.20220116004912.el8ost.noarch.rpm<\/p>\n<p dir=\"ltr\">These packages are GPG signed by Red Hat for security. Our key and<br \/>\ndetails on how to verify the signature are available from<br \/>\nhttps:\/\/access.redhat.com\/security\/team\/key\/<\/p>\n<p dir=\"ltr\">7. References:<\/p>\n<p dir=\"ltr\">https:\/\/access.redhat.com\/security\/cve\/CVE-2021-4180<br \/>\nhttps:\/\/access.redhat.com\/security\/updates\/classification\/#moderate<\/p>\n<p dir=\"ltr\">8. Contact:<\/p>\n<p dir=\"ltr\">The Red Hat security contact is &lt;secalert@redhat.com&gt;. More contact<br \/>\ndetails at https:\/\/access.redhat.com\/security\/team\/contact\/<\/p>\n<p dir=\"ltr\">Copyright 2022 Red Hat, Inc.<br \/>\n&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<br \/>\nVersion: GnuPG v1<\/p>\n<p dir=\"ltr\">iQIVAwUBYjvmKNzjgjWX9erEAQispxAAihi4ziFGX97tUuSGWQgConiT5Hewws7X<br \/>\n84GxTMJ82iW7M7bQBPW6+YaKsKqqt3Yd3+1qCJG2q4A1j8dR\/9Cy9U93AHHqMZe+<br \/>\nHOALT\/1JQzrmH\/DZGkuj5buhaHLYxbeBv\/3IlyoaZVPRhu8xZ6wD\/1OnPPTkc0LA<br \/>\nHrEc47t5bVTmAqMyTdnBi5+0FxmgabOErSZk2MaWfTiBUpDbZfgO4Nw6Kq0UZyG1<br \/>\nq72gOnR6ZPCZG3n+QDIZytifEW9wCpngF8H5lOYe+BLErmBySUGtQubWllBA02Go<br \/>\nDXIb4pPmtc7O08CVywTfdxAFTdaE69pk7LhB9\/XRRVeLMkHc7ICKqtJmNXkyYugW<br \/>\n6zI\/F950TzTqHlx7cRnEOY44D3sHva3CMy2QQHgz93FPiSdnNktLimP116jJHUfZ<br \/>\nR6BAg4nBU8T1scTf0SBTurJeVhmOh9r5zyGRSzdDKA\/iS6qY0u\/RTzaQKLZrM2fl<br \/>\nBPKbyZwQPFvGYepjBtSbKEbdXihz+b03N2KDg7XI4RP7z6k\/qHnUAJ9lNIt9t9gI<br \/>\nhJmiKyGAzrHKNqkuzXrMRhOnbfgElzMI2epsfUtYSfx3cga6NB4fQafT+YVZotLJ<br \/>\n1DkCfWDmwr\/6qVqMNfqLh4KhC1WjwwYKFeqz5VYbNagEhe2Zn7ALIBc+b4xjp+8E<br \/>\nUKkhXd7aiwk=<br \/>\n=yB4a<br \/>\n&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<br \/>\n&#8212;<br \/>\nRHSA-announce mailing list<br \/>\nRHSA-announce@redhat.com<br \/>\nhttps:\/\/listman.redhat.com\/mailman\/listinfo\/rhsa-announce<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211; Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat OpenStack Platform 16.2 (openstack-tripleo-heat-templates) security update Advisory ID: RHSA-2022:0995-01 Product: Red Hat OpenStack Platform Advisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2022:0995 Issue date: 2022-03-23 CVE Names: CVE-2021-4180 ===================================================================== 1. Summary: An update for openstack-tripleo-heat-templates is now available for Red Hat OpenStack Platform 16.2 (Train). &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-22105","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/22105","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=22105"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/22105\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=22105"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=22105"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=22105"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}