- Issued:
- 2015-10-08
- Updated:
- 2015-10-08
RHSA-2015:1862 - Security Advisory
Synopsis
Moderate: Red Hat Enterprise Linux OpenStack Platform 7 director update
Type/Severity
Security Advisory: Moderate
Red Hat Insights patch analysis
Identify and remediate systems affected by this advisory.
Topic
Updated packages that fix one security issue, several bugs, and add various
enhancements are now available for Red Hat Enterprise Linux OpenStack
Platform 7.0 director for Red Hat Enterprise Linux 7.
Red Hat Product Security has rated this update as having Moderate security
impact. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available from the CVE link in the
References section.
Description
Red Hat Enterprise Linux OpenStack Platform director provides the
facilities for deploying and monitoring a private or public
infrastructure-as-a-service (IaaS) cloud based on Red Hat Enterprise Linux
OpenStack Platform.
A flaw was discovered in the pipeline ordering of OpenStack Object
Storage's staticweb middleware in the swiftproxy configuration generated
from the openstack-tripleo-heat-templates package (OpenStack director).
The staticweb middleware was incorrectly configured before the Identity
Service, and under some conditions an attacker could use this flaw to gain
unauthenticated access to private data. (CVE-2015-5271)
This issue was discovered by Christian Schwede and Emilien Macchi of
Red Hat.
This update also fixes numerous bugs and adds various enhancements.
Space precludes documenting all of these changes in this advisory.
Users are directed to the Red Hat Enterprise Linux OpenStack Platform 7
Release Notes, linked to in the References section, for information on the
most significant of these changes.
All Red Hat Enterprise Linux OpenStack Platform 7.0 director users are
advised to upgrade to these updated packages, which correct these issues
and add these enhancements.
Solution
Before applying this update, make sure all previously released errata
relevant to your system have been applied.
For details on how to apply this update, refer to:
Affected Products
- Red Hat OpenStack 7 x86_64
Fixes
- BZ - 1223022 - Ceilometer API port not allowed in firewall rules on undercloud
- BZ - 1226376 - Neutron API port not allowed in firewall rules on undercloud
- BZ - 1228862 - Can `openstack undercloud install` have a --force-clean option so an error doesn't require restarting?
- BZ - 1231777 - Its possible to scale up beyond the number of free nodes
- BZ - 1233949 - overcloud horizon apache config doesn't appear to use a network vip
- BZ - 1235320 - Unhelpful failure when incorrect parameters are given
- BZ - 1235325 - "openstack baremetal configure boot" should skip nodes that have maintenance=true
- BZ - 1236136 - All overcloud keystone endpoints get configured with the public IP when using network isolation
- BZ - 1236663 - No output for upload images command
- BZ - 1236707 - undercloud.conf.sample incorrectly states that heat db encryption key can be 8,16, or 32 chars
- BZ - 1237020 - undercloud GUI- Image field is mandatory when setting VM for deploy overcloud
- BZ - 1240260 - introspection timed out for 2 VM nodes
- BZ - 1241199 - openstack baremetal configure boot is not safe to run a second time
- BZ - 1241668 - 'openstack help overcloud deploy' : doesn't cover comments/explanation for all deployment --arguments
- BZ - 1243015 - Overcloud stack name hard-coded
- BZ - 1243032 - Hard-coded reference to instackenv.json
- BZ - 1243062 - On deployment failure, no reason is returned
- BZ - 1243121 - Neutron port quota fails larger overcloud deployments
- BZ - 1243472 - don't save UpdateIdentifier in tuskar when running package update
- BZ - 1243601 - Overcloud deploys default to qemu instead of kvm
- BZ - 1243829 - overcloud image upload creates duplicate images
- BZ - 1244001 - bulk introspection with active nodes fails
- BZ - 1244026 - [RFE] Overcloud nodes deployed by OSP-Director are using DHCP; can they be statically assigned instead?
- BZ - 1244032 - [RFE] Can OSP-Director deploy an HA overcloud which uses a hardware load balancer?
- BZ - 1244856 - openstack overcloud update stack overcloud requires an undocumented argument
- BZ - 1244864 - VXLAN should be default neutron network type
- BZ - 1245212 - rhel-osp-director: Running "ahc-match" on a setup with enabled SSL yields error: ironicclient.openstack.common.apiclient.exceptions.ConnectionRefused: Error communicating with https://[IP]:13385/ [Errno 1] _ssl.c:504: error:14090086:SSL routines:SSL
- BZ - 1245714 - set mem overcommit to 1:1
- BZ - 1246596 - Add support for network validation tests
- BZ - 1247015 - openstack undercloud install doesn't create rabbit user if you set custom passwords in undercloud.conf
- BZ - 1247722 - messages report Introspection for one of the nodes 'has timed out' while the command returns ' Discovery completed.'
- BZ - 1248172 - inspection: clean failed with pxe_ilo
- BZ - 1249640 - Installers need to configure tempest with deployment-specific values and export a partial tempest.conf
- BZ - 1250249 - After deploying, system load charts shown on the overview page are incorrect
- BZ - 1250250 - When deploying from UI we miss to add params based on scale logic
- BZ - 1251566 - Undercloud mariadb max_connection default is too low
- BZ - 1252054 - Default deployment through GUI doesn't create cinder v2 service and endpoint
- BZ - 1252219 - ovs bond on controller is not seeing dhcp packet
- BZ - 1252437 - [Discovery] Gathers wrong information about disks available
- BZ - 1252509 - rhel-osp-director: Fail to "openstack overcloud update stack": "ERROR: openstack unexpected end of regular expression"
- BZ - 1252553 - rhel-osp-director: UI: Limited selection for public interface under service configuration.
- BZ - 1253465 - [RFE] Allow for customization of the Ceph pools name and client username
- BZ - 1253628 - external ceph patches break tuskar based deploys
- BZ - 1253777 - HA overcloud deployment argument for NTP server should not be optional
- BZ - 1254897 - Not configuring neutron mechanism drivers in any puppet based deploys
- BZ - 1255910 - overcloud node delete of one compute node removed all of them
- BZ - 1255931 - rhel-osp-director: rhel-osp-director: unable to delete a heat stack deployed with "--rhel-reg --reg-method portal --reg-org <rel-org> --reg-activation-key '<key>'", following a failed attempt to update it with "openstack overcloud update stack --templates
- BZ - 1256477 - ironic ipmitool intermittently timing out causing API requests to process slowly
- BZ - 1257414 - [HA] critical resource constraints missing from pacemaker config make things go kaboom
- BZ - 1257642 - yum hanged infinitely on nova-compute cleanup when do an update
- BZ - 1259393 - [RFE] Add support to register and deploy nodes with fake_pxe
- BZ - 1259905 - Integrate yum updates of overcloud with Puppet
- BZ - 1260736 - missing module python-ironic-inspector-client
- BZ - 1260991 - Running the same deploy command twice results with :"Deployment failed: Not enough nodes - available: 2, requested: 5"
- BZ - 1261045 - Big Switch ML2 networking plugin configuration
- BZ - 1261048 - controllerExtraConfig support
- BZ - 1261067 - Keystone notifications support
- BZ - 1261697 - CVE-2015-5271 openstack-tripleo-heat-templates: unsafe pipeline ordering of swift staticweb middleware
- BZ - 1261921 - updating overcloud stack packages doesn't stop cluster and will cause it to be down
- BZ - 1262059 - Include the bigswitch networking packages in the image by default
- BZ - 1262454 - os-cloud-config: with fake_pxe pm_type in instackenv.json and thus no pm_addr entry, "openstack baremetal import --json instackenv.json" exits with: ERROR: openstack 'pm_addr'
- BZ - 1262995 - osp-d deployment fails on network validation scripts when network-isolation is not enabled.
- BZ - 1265010 - Heat environment is overwritten on overcloud updates
- BZ - 1265777 - No DNS servers set on the overcloud nodes
- BZ - 1266082 - RHEL unregistration doesn't work when scaling down
- BZ - 1266253 - [Director] increase mariadb max_connection default value
- BZ - 1266327 - yum_update.sh fails due to incomplete --excludes list
- BZ - 1266911 - CLI should not force --neutron-tunnel-types if --neutron-disable-tunneling is specified
- BZ - 1267883 - Unable to control the file_descriptors limit for rabbitmq-server via the director.
CVEs
Red Hat OpenStack 7
SRPM | |
---|---|
ahc-tools-0.1.1-6.el7ost.src.rpm | SHA-256: 8b5ff970390b0523122f536a6e989dd8b5be68db51ec178313c9bdecd64655eb |
instack-undercloud-2.1.2-29.el7ost.src.rpm | SHA-256: 71a1d7d5ebaddc76de98d424faf858bda1b6cdeed3a97a856bc27e9dd6f657bc |
openstack-ironic-discoverd-1.1.0-6.el7ost.src.rpm | SHA-256: ef06ce09a1d6f7e70d49e3d77aa6421338ddb6aedf6679ea4bba2c01ef268504 |
openstack-tripleo-common-0.0.1.dev6-3.git49b57eb.el7ost.src.rpm | SHA-256: b449b821eb1ddbdd70920a504d694c4fd2b52f4a1807bb9aafe71d63ef3523fa |
openstack-tripleo-heat-templates-0.8.6-71.el7ost.src.rpm | SHA-256: b67860a8c5c2c3af347bb25b49a01db7ad14fc28304fecad78ced1d91692c8d9 |
openstack-tripleo-image-elements-0.9.6-10.el7ost.src.rpm | SHA-256: f9f1614fa223a8d7b63b5e172ea565528ef1fca40099e3f9cab373e7039e3102 |
openstack-tripleo-puppet-elements-0.0.1-5.el7ost.src.rpm | SHA-256: b681ac5bf3306a9b415650ac0bbdd1262f4ffb5f5db5b8996ce9265cb36259f1 |
openstack-tuskar-0.4.18-4.el7ost.src.rpm | SHA-256: 0cbbc36f24dd59a9e67c6daef0095afe2cfe0dc10e91a02909524d55bbe24eb9 |
openstack-tuskar-ui-0.4.0-3.el7ost.src.rpm | SHA-256: 5a12a99d6a7d7e32540a9613f7547d698148de4c7cd12677ff64651489f1f3a7 |
os-cloud-config-0.2.8-7.el7ost.src.rpm | SHA-256: 9ec929da69f760f4562258a724b8ecea36b0ba27f37f04a7476cb235bb682ec1 |
os-net-config-0.1.4-4.el7ost.src.rpm | SHA-256: 698b932141ed3e28655c586bfce1fa7609c13f24984299b5ffe976ad4d142fdc |
python-hardware-0.14-7.el7ost.src.rpm | SHA-256: 0f2dba594275afad0124d2212889ebe57d8ed26b9565bb8af3c5e98a6572c51f |
python-proliantutils-2.1.0-4.el7ost.src.rpm | SHA-256: a38c84dadf8bdef99ecde45c8e62170223db70f1c86f2b0e5c825179a08980fb |
python-rdomanager-oscplugin-0.0.10-8.el7ost.src.rpm | SHA-256: 33eb6b38298bd3f414f38c3a99bcb6b7b9b2b1d3dd6a562c69590a0e0a40b850 |
x86_64 | |
ahc-tools-0.1.1-6.el7ost.noarch.rpm | SHA-256: 1c80ca65fbefd14499158b4ed25bb8633e97a1dfb421dc56129bebc3029faf02 |
instack-undercloud-2.1.2-29.el7ost.noarch.rpm | SHA-256: 3e4fe34d748ab144f29d4686133325e4191d1ba27244ab76923d857ed9ab3448 |
openstack-ironic-discoverd-1.1.0-6.el7ost.noarch.rpm | SHA-256: 4466e79806fab1b44e0a6a907ec34515e2418e502af29f51023f381f3e0311e6 |
openstack-ironic-discoverd-ramdisk-1.1.0-6.el7ost.noarch.rpm | SHA-256: 5ba19417de493d76a520c5af4e833760a4ad1809d2993a513b92e2fd56e06da2 |
openstack-tripleo-common-0.0.1.dev6-3.git49b57eb.el7ost.noarch.rpm | SHA-256: 467f8266d9a9d98b751f22fc4673854ef72e5d1680537846d7bf6650a684803d |
openstack-tripleo-heat-templates-0.8.6-71.el7ost.noarch.rpm | SHA-256: ef603c1bda5cc35485fbb8ebd78b1587f7bb031ae7cd70d2f7e854de2aed8652 |
openstack-tripleo-image-elements-0.9.6-10.el7ost.noarch.rpm | SHA-256: e93104df0a412fb29b99dc1de57af2f5dd23f5cc65cb4d43b24f0afc2c9b6ed3 |
openstack-tripleo-puppet-elements-0.0.1-5.el7ost.noarch.rpm | SHA-256: 2e95d17c21bc8664a6520fffadab9870c4af6c0ea8d9ebd4833a801f144a74f9 |
openstack-tuskar-0.4.18-4.el7ost.noarch.rpm | SHA-256: aa354c79a30411cd86d76a689533a55c5a44b99fd3de49c3dbe7162cd2d43364 |
openstack-tuskar-ui-0.4.0-3.el7ost.noarch.rpm | SHA-256: 5b16e52b08a3e6e055b50425850e4380af814891cdc688500f3e2752e0e559fa |
os-cloud-config-0.2.8-7.el7ost.noarch.rpm | SHA-256: d2df9bbcf8702eb46a0fabcc6eebae3a3f459fe68b466b89e19688aeffdc96a4 |
os-net-config-0.1.4-4.el7ost.noarch.rpm | SHA-256: 97db9b2280add28eb2772fdf90a1ad8d050fbe2b204a925f66d00d845a18cc14 |
python-hardware-0.14-7.el7ost.noarch.rpm | SHA-256: 381d6373996a5cc964c600988cc2576a20e15e067fe19316fc77177edbda3bef |
python-hardware-doc-0.14-7.el7ost.noarch.rpm | SHA-256: 244e322b2e244cc518526520a91915c42d9ca64eee054f08e5459ec07187e8ee |
python-ironic-discoverd-1.1.0-6.el7ost.noarch.rpm | SHA-256: 9b4adb9962b985dec696c2b46c2e0e78796259c2d055ea04dad7edfadb314172 |
python-proliantutils-2.1.0-4.el7ost.noarch.rpm | SHA-256: d45506f78694e19ecbce09a58ae81051b6f9a5e3f75c564ff2387f069bce1343 |
python-rdomanager-oscplugin-0.0.10-8.el7ost.noarch.rpm | SHA-256: c81a3ecafc004dce09f7e971726bbf2b972a8826cf5c1d4c79a463f86f281250 |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.