openSUSE2021:0544-1: moderate: Security update for ceph

openSUSE Security Update: Security update for ceph ______________________________________________________________________________
Announcement ID: openSUSE-SU-2021:0544-1 Rating: moderate References: #1172926 #1176390 #1176489 #1176679 #1176828 #1177360 #1177857 #1178837 #1178860 #1178905 #1178932 #1179569 #1179997 #1182766 Cross-References: CVE-2020-25678 CVE-2020-27839 CVSS scores: CVE-2020-25678 (NVD) : 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N CVE-2020-27839 (SUSE): 4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________
An update that solves two vulnerabilities and has 12 fixes is now available.
This update for ceph fixes the following issues:
– ceph was updated to to 15.2.9 – cephadm: fix ‘inspect’ and ‘pull’ (bsc#1182766) – CVE-2020-27839: mgr/dashboard: Use secure cookies to store JWT Token (bsc#1179997) – CVE-2020-25678: Do not add sensitive information in Ceph log files (bsc#1178905) – mgr/orchestrator: Sort ‘ceph orch device ls’ by host (bsc#1172926) – mgr/dashboard: enable different URL for users of browser to Grafana (bsc#1176390, bsc#1176679) – mgr/cephadm: lock multithreaded access to OSDRemovalQueue (bsc#1176489) – cephadm: command_unit: call systemctl with verbose=True (bsc#1176828) – cephadm: silence “Failed to evict container” log msg (bsc#1177360) – mgr/cephadm: upgrade: fail gracefully, if daemon redeploy fails (bsc#1177857) – rgw: cls/user: set from_index for reset stats calls (bsc#1178837) – mgr/dashboard: Disable TLS 1.0 and 1.1 (bsc#1178860) – cephadm: reference the last local image by digest (bsc#1178932, bsc#1179569)
This update was imported from the SUSE:SLE-15-SP2:Update update project.
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or “zypper patch”.
Alternatively you can run the command listed for your product:
– openSUSE Leap 15.2:
zypper in -t patch openSUSE-2021-544=1

Package List:
– openSUSE Leap 15.2 (x86_64):
ceph- ceph-base- ceph-base-debuginfo- ceph-common- ceph-common-debuginfo- ceph-debugsource- ceph-fuse- ceph-fuse-debuginfo- ceph-immutable-object-cache- ceph-immutable-object-cache-debuginfo- ceph-mds- ceph-mds-debuginfo- ceph-mgr- ceph-mgr-debuginfo- ceph-mon- ceph-mon-debuginfo- ceph-osd- ceph-osd-debuginfo- ceph-radosgw- ceph-radosgw-debuginfo- ceph-test- ceph-test-debuginfo- ceph-test-debugsource- cephfs-shell- libcephfs-devel- libcephfs2- libcephfs2-debuginfo- librados-devel- librados-devel-debuginfo- librados2- librados2-debuginfo- libradospp-devel- librbd-devel- librbd1- librbd1-debuginfo- librgw-devel- librgw2- librgw2-debuginfo- python3-ceph-argparse- python3-ceph-common- python3-cephfs- python3-cephfs-debuginfo- python3-rados- python3-rados-debuginfo- python3-rbd- python3-rbd-debuginfo- python3-rgw- python3-rgw-debuginfo- rados-objclass-devel- rbd-fuse- rbd-fuse-debuginfo- rbd-mirror- rbd-mirror-debuginfo- rbd-nbd- rbd-nbd-debuginfo-
– openSUSE Leap 15.2 (noarch):
ceph-grafana-dashboards- ceph-mgr-cephadm- ceph-mgr-dashboard- ceph-mgr-diskprediction-cloud- ceph-mgr-diskprediction-local- ceph-mgr-k8sevents- ceph-mgr-modules-core- ceph-mgr-rook- ceph-prometheus-alerts- cephadm-