Red Hat Security Advisory 2024-9978-03 - An update for openstack-tripleo-heat-templates is now available for Red Hat OpenStack Platform 17.1.
1c80192dfd41da95ebee41d2ac4dc81927c0dfa75eb0ed9878804e77629c1507
The following advisory data is extracted from:
https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_9978.json
Red Hat officially shut down their mailing list notifications October 10, 2023. Due to this, Packet Storm has recreated the below data as a reference point to raise awareness. It must be noted that due to an inability to easily track revision updates without crawling Red Hat's archive, these advisories are single notifications and we strongly suggest that you visit the Red Hat provided links to ensure you have the latest information available if the subject matter listed pertains to your environment.
- Packet Storm Staff
====================================================================
Red Hat Security Advisory
Synopsis: Moderate: RHOSP 17.1.4 (openstack-tripleo-heat-templates) security update
Advisory ID: RHSA-2024:9978-03
Product: Red Hat OpenStack Platform
Advisory URL: https://access.redhat.com/errata/RHSA-2024:9978
Issue date: 2024-11-25
Revision: 03
CVE Names: CVE-2024-4840
====================================================================
Summary:
An update for openstack-tripleo-heat-templates is now available for Red Hat
OpenStack Platform (RHOSP) 17.1 (Wallaby).
Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.
Description:
Heat templates for TripleO
Security Fix(es):
* cleartext passwords exposed in logs (CVE-2024-4840)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page listed in the References section.
Solution:
https://access.redhat.com/articles/11258
CVEs:
CVE-2024-4840
References:
https://access.redhat.com/security/updates/classification/#moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2235206
https://bugzilla.redhat.com/show_bug.cgi?id=2242069
https://bugzilla.redhat.com/show_bug.cgi?id=2243267
https://bugzilla.redhat.com/show_bug.cgi?id=2247302
https://bugzilla.redhat.com/show_bug.cgi?id=2249881
https://bugzilla.redhat.com/show_bug.cgi?id=2252442
https://bugzilla.redhat.com/show_bug.cgi?id=2255302
https://bugzilla.redhat.com/show_bug.cgi?id=2264238
https://bugzilla.redhat.com/show_bug.cgi?id=2269219
https://bugzilla.redhat.com/show_bug.cgi?id=2274355
https://bugzilla.redhat.com/show_bug.cgi?id=2275307
https://bugzilla.redhat.com/show_bug.cgi?id=2276136
https://bugzilla.redhat.com/show_bug.cgi?id=2276592
https://bugzilla.redhat.com/show_bug.cgi?id=2276865
https://bugzilla.redhat.com/show_bug.cgi?id=2278019
https://bugzilla.redhat.com/show_bug.cgi?id=2279464
https://bugzilla.redhat.com/show_bug.cgi?id=2279998
https://bugzilla.redhat.com/show_bug.cgi?id=2280249
https://bugzilla.redhat.com/show_bug.cgi?id=2284645
https://bugzilla.redhat.com/show_bug.cgi?id=2290685
https://bugzilla.redhat.com/show_bug.cgi?id=2293048
https://bugzilla.redhat.com/show_bug.cgi?id=2293735
https://bugzilla.redhat.com/show_bug.cgi?id=2295402
https://bugzilla.redhat.com/show_bug.cgi?id=2295757
https://bugzilla.redhat.com/show_bug.cgi?id=2295948
https://bugzilla.redhat.com/show_bug.cgi?id=2302191
https://bugzilla.redhat.com/show_bug.cgi?id=2303551
https://bugzilla.redhat.com/show_bug.cgi?id=2304312
https://bugzilla.redhat.com/show_bug.cgi?id=2305981
https://bugzilla.redhat.com/show_bug.cgi?id=2306489
https://bugzilla.redhat.com/show_bug.cgi?id=2307256
https://bugzilla.redhat.com/show_bug.cgi?id=2307307
https://bugzilla.redhat.com/show_bug.cgi?id=2310427
https://bugzilla.redhat.com/show_bug.cgi?id=2311465
https://bugzilla.redhat.com/show_bug.cgi?id=2313372
https://bugzilla.redhat.com/show_bug.cgi?id=2313502
https://bugzilla.redhat.com/show_bug.cgi?id=2314658
https://bugzilla.redhat.com/show_bug.cgi?id=2316083
https://bugzilla.redhat.com/show_bug.cgi?id=2320400