Category Archives: Advisories

USN-6073-1: Cinder vulnerability

Read Time:17 Second

Jan Wasilewski and Gorka Eguileor discovered that Cinder incorrectly
handled deleted volume attachments. An authenticated user or attacker could
possibly use this issue to gain access to sensitive information.

This update may require configuration changes to be completely effective,
please see the upstream advisory for more information:

https://security.openstack.org/ossa/OSSA-2023-003.html

Read More

python-waitress-1.4.3-1.el8

Read Time:21 Second

FEDORA-EPEL-2023-9191f31d36

Packages in this update:

python-waitress-1.4.3-1.el8

Update description:

This update takes the package from version 1.2.1 to version 1.4.3. This is necessary to fix multiple CVEs.

CVE-2019-16785 (high)
CVE-2019-16786 (high)
CVE-2019-16789 (high)
CVE-2019-16792 (high)
CVE-2020-5236 (medium)

There are no breaking changes mentioned in the upstream changelog.

Read More