-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Moderate: openstack-manila security update
Advisory ID:       RHSA-2020:1326-01
Product:           Red Hat OpenStack Platform
Advisory URL:      https://access.redhat.com/errata/RHSA-2020:1326
Issue date:        2020-04-06
CVE Names:         CVE-2020-9543 
====================================================================
1. Summary:

An update for openstack-manila is now available for Red Hat OpenStack
Platform 15 (Stein).

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat OpenStack Platform 15.0 - noarch

3. Description:

OpenStack Shared Filesystem Service (Manila) provides services to manage
network filesystems for use by Virtual Machine instances.

Security Fix(es):

* User with share-network UUID is able to show create and delete shares
(CVE-2020-9543)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page listed in the References section.

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

5. Bugs fixed (https://bugzilla.redhat.com/):

1809855 - CVE-2020-9543 openstack-manila: User with share-network UUID  is able to show, create and delete shares

6. Package List:

Red Hat OpenStack Platform 15.0:

Source:
openstack-manila-8.1.1-0.20200311070441.17b29e2.el8ost.src.rpm

noarch:
openstack-manila-8.1.1-0.20200311070441.17b29e2.el8ost.noarch.rpm
openstack-manila-share-8.1.1-0.20200311070441.17b29e2.el8ost.noarch.rpm
python3-manila-8.1.1-0.20200311070441.17b29e2.el8ost.noarch.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2020-9543
https://access.redhat.com/security/updates/classification/#moderate

8. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2020 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBXorwStzjgjWX9erEAQidQQ//fbfjjPxAkLKzMTDlLMpfJjgwe41cT102
XbwydHSzwFEKJhm/klR/LrsPyzEio1x7syYz0VONC7R066tZJ8nPkT65mb6ELn1A
8EvZzuc+5G+FSxfpkIvkS8SUOL9k+ShKuhi9hufk33jZYx2cv2/uuByxV3Cek5rp
FzipMcnFwEnBNMFeQxYtPwoj0yJUFuoWU1McVfoVIb/iCaWow0BmaqGguI+5sycC
bNKyxnT4z5A9W4PR83q6uAHk+IR1Ce8MoYGlPb60DVZmWxfvnaD31wwliWYvehwp
QGA6Xw66KcMMkt3e7pn4fTor/gOvNJ934AFAUFjxGtp40dNiBpsYMbW5ssAawOlj
VijtVI2phBJjGSOLWXcC/nD/UG8QI1wkzzMPRMR07jkue4gZV3CWJvadhzWqQrxm
VURyLFzuTH3aVmiCR333MzlPgAo4d3Bl2P4eDH6+Mmnt6LGS69kHHxPLvkDeKyQB
y2beNLVqb4O4+Fp+OkqxgVd3ZUhE3IXCwiDCGzitasDDWEEsLumDUQM57r/xZuxP
9WtWdL5vkq1wGjCCf+Xtebq3z1WpuyQKYOmxKjfuA3iU0szRI/fTfcqkI7/UZ9sY
VB0Cuj8RaMJGiLQ7MikYq1ja5Zko5hE8nhUCSnKrvlVNz1aCujqgi+hf1s+vZQop
+QYKahlDprs=HlCG
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2020-1326:01 Moderate: openstack-manila security update

An update for openstack-manila is now available for Red Hat OpenStack Platform 15 (Stein)

Summary

OpenStack Shared Filesystem Service (Manila) provides services to manage network filesystems for use by Virtual Machine instances.
Security Fix(es):
* User with share-network UUID is able to show create and delete shares (CVE-2020-9543)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section.



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2020-9543 https://access.redhat.com/security/updates/classification/#moderate

Package List

Red Hat OpenStack Platform 15.0:
Source: openstack-manila-8.1.1-0.20200311070441.17b29e2.el8ost.src.rpm
noarch: openstack-manila-8.1.1-0.20200311070441.17b29e2.el8ost.noarch.rpm openstack-manila-share-8.1.1-0.20200311070441.17b29e2.el8ost.noarch.rpm python3-manila-8.1.1-0.20200311070441.17b29e2.el8ost.noarch.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/


Severity
Advisory ID: RHSA-2020:1326-01
Product: Red Hat OpenStack Platform
Advisory URL: https://access.redhat.com/errata/RHSA-2020:1326
Issued Date: : 2020-04-06
CVE Names: CVE-2020-9543

Topic

An update for openstack-manila is now available for Red Hat OpenStackPlatform 15 (Stein).Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures

Red Hat OpenStack Platform 15.0 - noarch


Bugs Fixed

1809855 - CVE-2020-9543 openstack-manila: User with share-network UUID is able to show, create and delete shares


Related News