SUSE-SU-2018:2765-1: moderate: Security update for couchdb
    sle-security-updates at lists.suse.com 
    sle-security-updates at lists.suse.com
       
    Thu Sep 20 04:16:47 MDT 2018
    
    
  
   SUSE Security Update: Security update for couchdb
______________________________________________________________________________
Announcement ID:    SUSE-SU-2018:2765-1
Rating:             moderate
References:         #1100973 
Cross-References:   CVE-2018-8007
Affected Products:
                    SUSE OpenStack Cloud Crowbar 8
______________________________________________________________________________
   An update that fixes one vulnerability is now available.
Description:
   This update for couchdb fixes the following security issues:
   - CVE-2018-8007: Apache CouchDB administrative users can configure the
     database server via HTTP(S). Due to insufficient validation of
     administrator-supplied configuration settings via the HTTP API, it was
     possible for a CouchDB administrator user to escalate their privileges
     to that of the operating system's user that CouchDB runs under, by
     bypassing the blacklist of configuration settings that are not allowed
     to be modified via the HTTP API (bsc#1100973)
Patch Instructions:
   To install this SUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".
   Alternatively you can run the command listed for your product:
   - SUSE OpenStack Cloud Crowbar 8:
      zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2018-1930=1
Package List:
   - SUSE OpenStack Cloud Crowbar 8 (x86_64):
      couchdb-1.7.2-3.3.1
      couchdb-debuginfo-1.7.2-3.3.1
      couchdb-debugsource-1.7.2-3.3.1
References:
   https://www.suse.com/security/cve/CVE-2018-8007.html
   https://bugzilla.suse.com/1100973
    
    
More information about the sle-security-updates
mailing list