{"affected":[{"ecosystem_specific":{"binaries":[{"grafana":"4.5.1-1.8.1","kafka":"0.10.2.2-5.1","logstash":"2.4.1-5.1","monasca-installer":"20180608_12.47-9.1"}]},"package":{"ecosystem":"SUSE:OpenStack Cloud 7","name":"grafana","purl":"pkg:rpm/suse/grafana&distro=SUSE%20OpenStack%20Cloud%207"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"4.5.1-1.8.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"grafana":"4.5.1-1.8.1","kafka":"0.10.2.2-5.1","logstash":"2.4.1-5.1","monasca-installer":"20180608_12.47-9.1"}]},"package":{"ecosystem":"SUSE:OpenStack Cloud 7","name":"kafka","purl":"pkg:rpm/suse/kafka&distro=SUSE%20OpenStack%20Cloud%207"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"0.10.2.2-5.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"grafana":"4.5.1-1.8.1","kafka":"0.10.2.2-5.1","logstash":"2.4.1-5.1","monasca-installer":"20180608_12.47-9.1"}]},"package":{"ecosystem":"SUSE:OpenStack Cloud 7","name":"logstash","purl":"pkg:rpm/suse/logstash&distro=SUSE%20OpenStack%20Cloud%207"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.4.1-5.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"grafana":"4.5.1-1.8.1","kafka":"0.10.2.2-5.1","logstash":"2.4.1-5.1","monasca-installer":"20180608_12.47-9.1"}]},"package":{"ecosystem":"SUSE:OpenStack Cloud 7","name":"monasca-installer","purl":"pkg:rpm/suse/monasca-installer&distro=SUSE%20OpenStack%20Cloud%207"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"20180608_12.47-9.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for grafana, kafka, logstash and monasca-installer fixes the following issues:\n\nThe following security issues have been fixed:\n\ngrafana:\n\n- CVE-2018-12099: Fix Cross-Site-Scripting (XSS) vulnerabilities in dashboard links. (bsc#1096985)\n\nkafka:\n\n- CVE-2018-1288: Authenticated Kafka users may perform action reserved for the Broker via a manually created fetch\n  request interfering with data replication, resulting in data loss. (bsc#1102920)\n\nlogstash:\n\n- CVE-2018-3817: Fix potential leak of sensitive data when logging warnings about deprecated options. (bsc#1090849)\n\nAdditionally, the following non-security issues have been fixed:\n\nmonasca-installer:\n\n- Add complete set of elasticsearch performance tunables.\n- Update to version Build_20180427_14.04 (bsc#1090192, bsc#1090343)\n- Fix bad elasticsearch-curator configuration. (bsc#1090192)\n- Enable bootstrap.memory_lock for Elasticsearch. (bsc#1090343)\n\nlogstash:\n\n- Declare Gemfile as config to prevent loss of installed plugins when updating.\n- Stop installing prebuilt jruby for non-x86.\n\nkafka: \n\n- Update to version 0.10.2.2 (bsc#1102920, CVE-2018-1288)\n- Add noreplace directive for /etc/kafka/server.properties.\n- Reduce package ownership of tmpfiles.d to bare minium. (SLE12 SP2) \n- Set log rotation options. (bsc#1094448)\n- Disable jmxremote debugging. (bsc#1095603)\n- Increase open file limits. (bsc#1086909)\n","id":"SUSE-SU-2018:2536-1","modified":"2018-08-28T09:05:28Z","published":"2018-08-28T09:05:28Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2018/suse-su-20182536-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1086909"},{"type":"REPORT","url":"https://bugzilla.suse.com/1090192"},{"type":"REPORT","url":"https://bugzilla.suse.com/1090343"},{"type":"REPORT","url":"https://bugzilla.suse.com/1090849"},{"type":"REPORT","url":"https://bugzilla.suse.com/1094448"},{"type":"REPORT","url":"https://bugzilla.suse.com/1095603"},{"type":"REPORT","url":"https://bugzilla.suse.com/1096985"},{"type":"REPORT","url":"https://bugzilla.suse.com/1102920"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-12099"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-1288"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-3817"}],"related":["CVE-2018-12099","CVE-2018-1288","CVE-2018-3817"],"summary":"Security update for grafana, kafka, logstash and monasca-installer","upstream":["CVE-2018-12099","CVE-2018-1288","CVE-2018-3817"]}