File _patchinfo of Package patchinfo.19392
<patchinfo incident="19392">
<issue tracker="bnc" id="1178860">SES6: Disable TLS 1.0 to fix CEPH nodes vulnerabilities</issue>
<issue tracker="bnc" id="1183074">VUL-0: CVE-2021-20288: ceph: Unauthorized global_id reuse</issue>
<issue tracker="bnc" id="1178235">SES6: SES Dashboard Nonexistent Page (404) Physical Path Disclosure</issue>
<issue tracker="bnc" id="1183487">As of Nautilus 14.2.17, Ceph Dashboard requires Python 2 for "import Cookie"</issue>
<issue tracker="bnc" id="1178837">L3-Question: What is the root cause of storage service stop?</issue>
<issue tracker="bnc" id="1180594">Customer needs all ceph traffic on the public network to be encrypted.</issue>
<issue tracker="bnc" id="1177200">SES6: missing package python3-python3-saml for dashboard single-sign-on</issue>
<issue tracker="bnc" id="1181378">run-cli-tests fails due to 10-year-old Python module ("cram")</issue>
<issue tracker="bnc" id="1180118">Running "ceph-bluestore-tool repair" after upgrade to SES 6 fails on one OSD</issue>
<issue tracker="bnc" id="1178905">VUL-1: CVE-2020-25678: ceph: ceph-dashboard: mgr modules' passwords are in clear text in mgr logs</issue>
<issue tracker="bnc" id="1179997">VUL-0: CVE-2020-27839: ceph: ceph-dashboard: Don't use Browser's LocalStorage for storing JWT but Secure Cookies with proper HTTP Headers</issue>
<issue tracker="bnc" id="1145463">network packets dropped is too aggressive</issue>
<issue tracker="bnc" id="1174466">'ceph mon stat -f json' is not giving json format output</issue>
<issue tracker="cve" id="2020-25678"/>
<issue tracker="cve" id="2021-20288"/>
<issue tracker="cve" id="2020-27839"/>
<packager>tserong</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for ceph</summary>
<description>This update for ceph fixes the following issues:
- ceph was updated to 14.2.20-402-g6aa76c6815:
* CVE-2021-20288: Fixed unauthorized global_id reuse (bsc#1183074).
* CVE-2020-25678: Do not add sensitive information in Ceph log files (bsc#1178905).
* CVE-2020-27839: Use secure cookies to store JWT Token (bsc#1179997).
* mgr/dashboard: prometheus alerting: add some leeway for package drops and errors (bsc#1145463)
* mon: have 'mon stat' output json as well (bsc#1174466)
* rpm: ceph-mgr-dashboard recommends python3-saml on SUSE (bsc#1177200)
* mgr/dashboard: Display a warning message in Dashboard when debug mode is enabled (bsc#1178235)
* rgw: cls/user: set from_index for reset stats calls (bsc#1178837)
* mgr/dashboard: Disable TLS 1.0 and 1.1 (bsc#1178860)
* bluestore: provide a different name for fallback allocator (bsc#1180118)
* test/run-cli-tests: use cram from github (bsc#1181378)
* mgr/dashboard: fix "Python2 Cookie module import fails on Python3" (bsc#1183487)
* common: make ms_bind_msgr2 default to 'false' (bsc#1180594)
</description>
</patchinfo>