UbuntuUpdates.org

Package "python-glance-store"

Name: python-glance-store

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • OpenStack Image Service store library - doc
  • OpenStack Image Service store library - Python 3.x

Latest version: 2.0.0-0ubuntu4.3
Release: focal (20.04)
Level: updates
Repository: main

Links



Other versions of "python-glance-store" in Focal

Repository Area Version
base main 2.0.0-0ubuntu1
security main 2.0.0-0ubuntu4.3

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 2.0.0-0ubuntu4.3 2024-02-12 16:06:54 UTC

  python-glance-store (2.0.0-0ubuntu4.3) focal-security; urgency=medium

  * SECURITY UPDATE: access_key logged in DEBUG log level
    - debian/patches/CVE-2024-1141-1.patch: do not show access_key in
      glance_store/_drivers/s3.py.
    - debian/patches/CVE-2024-1141-2.patch: fix more access_key logging in
      glance_store/_drivers/s3.py.
    - CVE-2024-1141

 -- Marc Deslauriers <email address hidden> Thu, 08 Feb 2024 13:51:06 -0500

Source diff to previous version
CVE-2024-1141 A vulnerability was found in python-glance-store. The issue occurs when the package logs the access_key for the glance-store when the DEBUG log level

Version: 2.0.0-0ubuntu4.2 2023-05-23 15:07:16 UTC

  python-glance-store (2.0.0-0ubuntu4.2) focal-security; urgency=medium

  * SECURITY REGRESSION: Regressions in other projects (LP: #2020111)
    - debian/patches/series: Do not apply CVE-2023-2088.patch until
      patches are ready for all upstream OpenStack projects.
    - CVE-2023-2088

 -- Corey Bryant <email address hidden> Thu, 18 May 2023 11:12:41 -0400

Source diff to previous version
CVE-2023-2088 OSSA-2023-003: Unauthorized volume access through deleted volume attachments

Version: 2.0.0-0ubuntu4.1 2023-05-11 20:07:13 UTC

  python-glance-store (2.0.0-0ubuntu4.1) focal-security; urgency=medium

  * SECURITY UPDATE: Unauthorized File Access
    - debian/patches/CVE-2023-2088.patch: Add force to os-brick
      disconnect.
    - CVE-2023-2088

 -- Corey Bryant <email address hidden> Tue, 09 May 2023 09:32:09 -0400

Source diff to previous version
CVE-2023-2088 OSSA-2023-003: Unauthorized volume access through deleted volume attachments

Version: 2.0.0-0ubuntu4 2022-12-06 19:06:26 UTC

  python-glance-store (2.0.0-0ubuntu4) focal; urgency=medium

  * d/p/ramp-up-rbd-resize-to-avoid-excessive-calls.patch: Cherry-picked
    from upstream to fix image upload performance with rbd backend
    (LP: #1983716).

 -- Corey Bryant <email address hidden> Fri, 05 Aug 2022 15:13:03 -0400

Source diff to previous version
1983716 Improve performances of glance when using rbd backend

Version: 2.0.0-0ubuntu3 2021-11-04 23:07:19 UTC

  python-glance-store (2.0.0-0ubuntu3) focal; urgency=medium

  * d/p/0001-Add-lock-per-share-for-cinder-nfs-mount-umount.patch: Cherry-picked
    from upstream to fix image creation failure with cinder as storage backend
    (LP: #1948439).

 -- Hemanth Nakkina <email address hidden> Fri, 22 Oct 2021 15:12:31 +0530

1948439 Not able to create image with cinder as storage backend



About   -   Send Feedback to @ubuntu_updates