Security notes

In total, in the MOSK 23.1.4 release, 8 Common Vulnerabilities and Exposures (CVE) have been fixed: 1 of critical and 7 of high severity.

The full list of the CVEs present in the current MOSK release is available at the Mirantis Security Portal.

Addressed CVEs

Image

Component name

CVE

openstack/extra/descheduler

golang.org/x/net

CVE-2022-41723 (High)

openstack/extra/powerdns

libpq

CVE-2023-2454 (High)

openstack/extra/strongswan

libcurl

CVE-2023-28319 (High)

CVE-2023-28321 (High)

CVE-2023-28322 (High)

libcap

CVE-2023-2603 (High)

openstack/horizon

django

CVE-2023-31047 (Critical)

openstack/manila

sqlparse

CVE-2023-30608 (High)