<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for ardana-ansible, ardana-monasca, documentation-suse-openstack-cloud, openstack-ec2-api, openstack-heat-templates, python-Django, python-monasca-common, rubygem-redcarpet, rubygem-puma</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2021:3728-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2021-11-19T12:37:40Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2021-11-19T12:37:40Z</InitialReleaseDate>
    <CurrentReleaseDate>2021-11-19T12:37:40Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for ardana-ansible, ardana-monasca, documentation-suse-openstack-cloud, openstack-ec2-api, openstack-heat-templates, python-Django, python-monasca-common, rubygem-redcarpet, rubygem-puma</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for ardana-ansible, ardana-monasca, documentation-suse-openstack-cloud, openstack-ec2-api, openstack-heat-templates, python-Django, python-monasca-common, rubygem-redcarpet, rubygem-puma contains the following fixes:

Security fixes included in this update:

rubygem-redcarpet:
CVE-2020-26298: Fixed XSS via HTML escaping when processing quotes. (bsc#1180837)

rubygem-puma:
CVE-2021-41136: Fixed build of the Java state machine for parsing HTTP. (bsc#1191681)

Non-security fixes included in this update:

Changes in ardana-ansible:
  * Patch service.py to skip blank lines.

Changes in ardana-monasca:
  * Use specific TLS versions for monasca-thresh DB connections. (SOC-11543)

Changes in documentation-suse-openstack-cloud:
  * CI: only run on DocBook/AsciiDoc paths, make upload fails nonfatal
  * DC files: Update to 2021 stylesheets (#1327)
  * CI: Use GitHub Actions

Changes in openstack-ec2-api:
  * Remove jobs corresponds to obselete featuresets
  * OpenDev Migration Patch

Changes in openstack-heat-templates:
  * [ussuri][goal] Update contributor documentation

Changes in python-Django:
- Add missing dependency for CVE-2021-31542

Changes in python-monasca-common:
- Remove renderspec source service.
- Retry publish once on failures. (SOC-11543)
  
  </Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">HPE-Helion-OpenStack-8-2021-3728,SUSE-2021-3728,SUSE-OpenStack-Cloud-8-2021-3728,SUSE-OpenStack-Cloud-Crowbar-8-2021-3728</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20213728-1/</URL>
      <Description>Link for SUSE-SU-2021:3728-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2021-November/009746.html</URL>
      <Description>E-Mail link for SUSE-SU-2021:3728-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1180837</URL>
      <Description>SUSE Bug 1180837</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1191681</URL>
      <Description>SUSE Bug 1191681</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-26298/</URL>
      <Description>SUSE CVE CVE-2020-26298 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-41136/</URL>
      <Description>SUSE CVE CVE-2021-41136 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="HPE Helion OpenStack 8">
      <Branch Type="Product Name" Name="HPE Helion OpenStack 8">
        <FullProductName ProductID="HPE Helion OpenStack 8" CPE="cpe:/o:suse:hpe-helion-openstack:8">HPE Helion OpenStack 8</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE OpenStack Cloud 8">
      <Branch Type="Product Name" Name="SUSE OpenStack Cloud 8">
        <FullProductName ProductID="SUSE OpenStack Cloud 8" CPE="cpe:/o:suse:suse-openstack-cloud:8">SUSE OpenStack Cloud 8</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE OpenStack Cloud Crowbar 8">
      <Branch Type="Product Name" Name="SUSE OpenStack Cloud Crowbar 8">
        <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 8" CPE="cpe:/o:suse:suse-openstack-cloud-crowbar:8">SUSE OpenStack Cloud Crowbar 8</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="ardana-ansible-8.0+git.1632499354.a56668f-3.82.1">
      <FullProductName ProductID="ardana-ansible-8.0+git.1632499354.a56668f-3.82.1">ardana-ansible-8.0+git.1632499354.a56668f-3.82.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ardana-monasca-8.0+git.1627997000.6c3bc04-3.30.1">
      <FullProductName ProductID="ardana-monasca-8.0+git.1627997000.6c3bc04-3.30.1">ardana-monasca-8.0+git.1627997000.6c3bc04-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="documentation-hpe-helion-openstack-installation-8.20210806-1.35.1">
      <FullProductName ProductID="documentation-hpe-helion-openstack-installation-8.20210806-1.35.1">documentation-hpe-helion-openstack-installation-8.20210806-1.35.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="documentation-hpe-helion-openstack-operations-8.20210806-1.35.1">
      <FullProductName ProductID="documentation-hpe-helion-openstack-operations-8.20210806-1.35.1">documentation-hpe-helion-openstack-operations-8.20210806-1.35.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="documentation-hpe-helion-openstack-opsconsole-8.20210806-1.35.1">
      <FullProductName ProductID="documentation-hpe-helion-openstack-opsconsole-8.20210806-1.35.1">documentation-hpe-helion-openstack-opsconsole-8.20210806-1.35.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="documentation-hpe-helion-openstack-planning-8.20210806-1.35.1">
      <FullProductName ProductID="documentation-hpe-helion-openstack-planning-8.20210806-1.35.1">documentation-hpe-helion-openstack-planning-8.20210806-1.35.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="documentation-hpe-helion-openstack-security-8.20210806-1.35.1">
      <FullProductName ProductID="documentation-hpe-helion-openstack-security-8.20210806-1.35.1">documentation-hpe-helion-openstack-security-8.20210806-1.35.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="documentation-hpe-helion-openstack-user-8.20210806-1.35.1">
      <FullProductName ProductID="documentation-hpe-helion-openstack-user-8.20210806-1.35.1">documentation-hpe-helion-openstack-user-8.20210806-1.35.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="openstack-ec2-api-5.0.1~dev12-4.9.1">
      <FullProductName ProductID="openstack-ec2-api-5.0.1~dev12-4.9.1">openstack-ec2-api-5.0.1~dev12-4.9.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="openstack-ec2-api-api-5.0.1~dev12-4.9.1">
      <FullProductName ProductID="openstack-ec2-api-api-5.0.1~dev12-4.9.1">openstack-ec2-api-api-5.0.1~dev12-4.9.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="openstack-ec2-api-metadata-5.0.1~dev12-4.9.1">
      <FullProductName ProductID="openstack-ec2-api-metadata-5.0.1~dev12-4.9.1">openstack-ec2-api-metadata-5.0.1~dev12-4.9.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="openstack-ec2-api-s3-5.0.1~dev12-4.9.1">
      <FullProductName ProductID="openstack-ec2-api-s3-5.0.1~dev12-4.9.1">openstack-ec2-api-s3-5.0.1~dev12-4.9.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="openstack-heat-templates-0.0.0+git.1628179051.7d761bf-3.24.1">
      <FullProductName ProductID="openstack-heat-templates-0.0.0+git.1628179051.7d761bf-3.24.1">openstack-heat-templates-0.0.0+git.1628179051.7d761bf-3.24.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python-Django-1.11.29-3.28.1">
      <FullProductName ProductID="python-Django-1.11.29-3.28.1">python-Django-1.11.29-3.28.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python-ec2api-5.0.1~dev12-4.9.1">
      <FullProductName ProductID="python-ec2api-5.0.1~dev12-4.9.1">python-ec2api-5.0.1~dev12-4.9.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python-monasca-common-2.3.1~dev4-4.9.1">
      <FullProductName ProductID="python-monasca-common-2.3.1~dev4-4.9.1">python-monasca-common-2.3.1~dev4-4.9.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="venv-openstack-heat-x86_64-9.0.8~dev22-12.35.1">
      <FullProductName ProductID="venv-openstack-heat-x86_64-9.0.8~dev22-12.35.1">venv-openstack-heat-x86_64-9.0.8~dev22-12.35.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="venv-openstack-horizon-hpe-x86_64-12.0.5~dev6-14.38.1">
      <FullProductName ProductID="venv-openstack-horizon-hpe-x86_64-12.0.5~dev6-14.38.1">venv-openstack-horizon-hpe-x86_64-12.0.5~dev6-14.38.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="venv-openstack-monasca-x86_64-2.2.2~dev1-11.30.1">
      <FullProductName ProductID="venv-openstack-monasca-x86_64-2.2.2~dev1-11.30.1">venv-openstack-monasca-x86_64-2.2.2~dev1-11.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="documentation-suse-openstack-cloud-deployment-8.20210806-1.35.1">
      <FullProductName ProductID="documentation-suse-openstack-cloud-deployment-8.20210806-1.35.1">documentation-suse-openstack-cloud-deployment-8.20210806-1.35.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="documentation-suse-openstack-cloud-installation-8.20210806-1.35.1">
      <FullProductName ProductID="documentation-suse-openstack-cloud-installation-8.20210806-1.35.1">documentation-suse-openstack-cloud-installation-8.20210806-1.35.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="documentation-suse-openstack-cloud-operations-8.20210806-1.35.1">
      <FullProductName ProductID="documentation-suse-openstack-cloud-operations-8.20210806-1.35.1">documentation-suse-openstack-cloud-operations-8.20210806-1.35.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="documentation-suse-openstack-cloud-opsconsole-8.20210806-1.35.1">
      <FullProductName ProductID="documentation-suse-openstack-cloud-opsconsole-8.20210806-1.35.1">documentation-suse-openstack-cloud-opsconsole-8.20210806-1.35.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="documentation-suse-openstack-cloud-planning-8.20210806-1.35.1">
      <FullProductName ProductID="documentation-suse-openstack-cloud-planning-8.20210806-1.35.1">documentation-suse-openstack-cloud-planning-8.20210806-1.35.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="documentation-suse-openstack-cloud-security-8.20210806-1.35.1">
      <FullProductName ProductID="documentation-suse-openstack-cloud-security-8.20210806-1.35.1">documentation-suse-openstack-cloud-security-8.20210806-1.35.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="documentation-suse-openstack-cloud-socmmsoperator-8.20210806-1.35.1">
      <FullProductName ProductID="documentation-suse-openstack-cloud-socmmsoperator-8.20210806-1.35.1">documentation-suse-openstack-cloud-socmmsoperator-8.20210806-1.35.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="documentation-suse-openstack-cloud-socmosoperator-8.20210806-1.35.1">
      <FullProductName ProductID="documentation-suse-openstack-cloud-socmosoperator-8.20210806-1.35.1">documentation-suse-openstack-cloud-socmosoperator-8.20210806-1.35.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="documentation-suse-openstack-cloud-socmoverview-8.20210806-1.35.1">
      <FullProductName ProductID="documentation-suse-openstack-cloud-socmoverview-8.20210806-1.35.1">documentation-suse-openstack-cloud-socmoverview-8.20210806-1.35.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="documentation-suse-openstack-cloud-supplement-8.20210806-1.35.1">
      <FullProductName ProductID="documentation-suse-openstack-cloud-supplement-8.20210806-1.35.1">documentation-suse-openstack-cloud-supplement-8.20210806-1.35.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="documentation-suse-openstack-cloud-upstream-admin-8.20210806-1.35.1">
      <FullProductName ProductID="documentation-suse-openstack-cloud-upstream-admin-8.20210806-1.35.1">documentation-suse-openstack-cloud-upstream-admin-8.20210806-1.35.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="documentation-suse-openstack-cloud-upstream-user-8.20210806-1.35.1">
      <FullProductName ProductID="documentation-suse-openstack-cloud-upstream-user-8.20210806-1.35.1">documentation-suse-openstack-cloud-upstream-user-8.20210806-1.35.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="documentation-suse-openstack-cloud-user-8.20210806-1.35.1">
      <FullProductName ProductID="documentation-suse-openstack-cloud-user-8.20210806-1.35.1">documentation-suse-openstack-cloud-user-8.20210806-1.35.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="openstack-ec2-api-test-5.0.1~dev12-4.9.1">
      <FullProductName ProductID="openstack-ec2-api-test-5.0.1~dev12-4.9.1">openstack-ec2-api-test-5.0.1~dev12-4.9.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-Django-1.11.29-3.28.1">
      <FullProductName ProductID="python3-Django-1.11.29-3.28.1">python3-Django-1.11.29-3.28.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ruby2.1-rubygem-puma-2.16.0-3.15.1">
      <FullProductName ProductID="ruby2.1-rubygem-puma-2.16.0-3.15.1">ruby2.1-rubygem-puma-2.16.0-3.15.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ruby2.1-rubygem-puma-doc-2.16.0-3.15.1">
      <FullProductName ProductID="ruby2.1-rubygem-puma-doc-2.16.0-3.15.1">ruby2.1-rubygem-puma-doc-2.16.0-3.15.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ruby2.1-rubygem-redcarpet-3.2.3-3.3.1">
      <FullProductName ProductID="ruby2.1-rubygem-redcarpet-3.2.3-3.3.1">ruby2.1-rubygem-redcarpet-3.2.3-3.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ruby2.1-rubygem-redcarpet-doc-3.2.3-3.3.1">
      <FullProductName ProductID="ruby2.1-rubygem-redcarpet-doc-3.2.3-3.3.1">ruby2.1-rubygem-redcarpet-doc-3.2.3-3.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ruby2.1-rubygem-redcarpet-testsuite-3.2.3-3.3.1">
      <FullProductName ProductID="ruby2.1-rubygem-redcarpet-testsuite-3.2.3-3.3.1">ruby2.1-rubygem-redcarpet-testsuite-3.2.3-3.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="venv-openstack-horizon-x86_64-12.0.5~dev6-14.38.2">
      <FullProductName ProductID="venv-openstack-horizon-x86_64-12.0.5~dev6-14.38.2">venv-openstack-horizon-x86_64-12.0.5~dev6-14.38.2</FullProductName>
    </Branch>
    <Relationship ProductReference="ardana-ansible-8.0+git.1632499354.a56668f-3.82.1" RelationType="Default Component Of" RelatesToProductReference="HPE Helion OpenStack 8">
      <FullProductName ProductID="HPE Helion OpenStack 8:ardana-ansible-8.0+git.1632499354.a56668f-3.82.1">ardana-ansible-8.0+git.1632499354.a56668f-3.82.1 as a component of HPE Helion OpenStack 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="ardana-monasca-8.0+git.1627997000.6c3bc04-3.30.1" RelationType="Default Component Of" RelatesToProductReference="HPE Helion OpenStack 8">
      <FullProductName ProductID="HPE Helion OpenStack 8:ardana-monasca-8.0+git.1627997000.6c3bc04-3.30.1">ardana-monasca-8.0+git.1627997000.6c3bc04-3.30.1 as a component of HPE Helion OpenStack 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="documentation-hpe-helion-openstack-installation-8.20210806-1.35.1" RelationType="Default Component Of" RelatesToProductReference="HPE Helion OpenStack 8">
      <FullProductName ProductID="HPE Helion OpenStack 8:documentation-hpe-helion-openstack-installation-8.20210806-1.35.1">documentation-hpe-helion-openstack-installation-8.20210806-1.35.1 as a component of HPE Helion OpenStack 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="documentation-hpe-helion-openstack-operations-8.20210806-1.35.1" RelationType="Default Component Of" RelatesToProductReference="HPE Helion OpenStack 8">
      <FullProductName ProductID="HPE Helion OpenStack 8:documentation-hpe-helion-openstack-operations-8.20210806-1.35.1">documentation-hpe-helion-openstack-operations-8.20210806-1.35.1 as a component of HPE Helion OpenStack 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="documentation-hpe-helion-openstack-opsconsole-8.20210806-1.35.1" RelationType="Default Component Of" RelatesToProductReference="HPE Helion OpenStack 8">
      <FullProductName ProductID="HPE Helion OpenStack 8:documentation-hpe-helion-openstack-opsconsole-8.20210806-1.35.1">documentation-hpe-helion-openstack-opsconsole-8.20210806-1.35.1 as a component of HPE Helion OpenStack 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="documentation-hpe-helion-openstack-planning-8.20210806-1.35.1" RelationType="Default Component Of" RelatesToProductReference="HPE Helion OpenStack 8">
      <FullProductName ProductID="HPE Helion OpenStack 8:documentation-hpe-helion-openstack-planning-8.20210806-1.35.1">documentation-hpe-helion-openstack-planning-8.20210806-1.35.1 as a component of HPE Helion OpenStack 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="documentation-hpe-helion-openstack-security-8.20210806-1.35.1" RelationType="Default Component Of" RelatesToProductReference="HPE Helion OpenStack 8">
      <FullProductName ProductID="HPE Helion OpenStack 8:documentation-hpe-helion-openstack-security-8.20210806-1.35.1">documentation-hpe-helion-openstack-security-8.20210806-1.35.1 as a component of HPE Helion OpenStack 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="documentation-hpe-helion-openstack-user-8.20210806-1.35.1" RelationType="Default Component Of" RelatesToProductReference="HPE Helion OpenStack 8">
      <FullProductName ProductID="HPE Helion OpenStack 8:documentation-hpe-helion-openstack-user-8.20210806-1.35.1">documentation-hpe-helion-openstack-user-8.20210806-1.35.1 as a component of HPE Helion OpenStack 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="openstack-ec2-api-5.0.1~dev12-4.9.1" RelationType="Default Component Of" RelatesToProductReference="HPE Helion OpenStack 8">
      <FullProductName ProductID="HPE Helion OpenStack 8:openstack-ec2-api-5.0.1~dev12-4.9.1">openstack-ec2-api-5.0.1~dev12-4.9.1 as a component of HPE Helion OpenStack 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="openstack-ec2-api-api-5.0.1~dev12-4.9.1" RelationType="Default Component Of" RelatesToProductReference="HPE Helion OpenStack 8">
      <FullProductName ProductID="HPE Helion OpenStack 8:openstack-ec2-api-api-5.0.1~dev12-4.9.1">openstack-ec2-api-api-5.0.1~dev12-4.9.1 as a component of HPE Helion OpenStack 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="openstack-ec2-api-metadata-5.0.1~dev12-4.9.1" RelationType="Default Component Of" RelatesToProductReference="HPE Helion OpenStack 8">
      <FullProductName ProductID="HPE Helion OpenStack 8:openstack-ec2-api-metadata-5.0.1~dev12-4.9.1">openstack-ec2-api-metadata-5.0.1~dev12-4.9.1 as a component of HPE Helion OpenStack 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="openstack-ec2-api-s3-5.0.1~dev12-4.9.1" RelationType="Default Component Of" RelatesToProductReference="HPE Helion OpenStack 8">
      <FullProductName ProductID="HPE Helion OpenStack 8:openstack-ec2-api-s3-5.0.1~dev12-4.9.1">openstack-ec2-api-s3-5.0.1~dev12-4.9.1 as a component of HPE Helion OpenStack 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="openstack-heat-templates-0.0.0+git.1628179051.7d761bf-3.24.1" RelationType="Default Component Of" RelatesToProductReference="HPE Helion OpenStack 8">
      <FullProductName ProductID="HPE Helion OpenStack 8:openstack-heat-templates-0.0.0+git.1628179051.7d761bf-3.24.1">openstack-heat-templates-0.0.0+git.1628179051.7d761bf-3.24.1 as a component of HPE Helion OpenStack 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-Django-1.11.29-3.28.1" RelationType="Default Component Of" RelatesToProductReference="HPE Helion OpenStack 8">
      <FullProductName ProductID="HPE Helion OpenStack 8:python-Django-1.11.29-3.28.1">python-Django-1.11.29-3.28.1 as a component of HPE Helion OpenStack 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-ec2api-5.0.1~dev12-4.9.1" RelationType="Default Component Of" RelatesToProductReference="HPE Helion OpenStack 8">
      <FullProductName ProductID="HPE Helion OpenStack 8:python-ec2api-5.0.1~dev12-4.9.1">python-ec2api-5.0.1~dev12-4.9.1 as a component of HPE Helion OpenStack 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-monasca-common-2.3.1~dev4-4.9.1" RelationType="Default Component Of" RelatesToProductReference="HPE Helion OpenStack 8">
      <FullProductName ProductID="HPE Helion OpenStack 8:python-monasca-common-2.3.1~dev4-4.9.1">python-monasca-common-2.3.1~dev4-4.9.1 as a component of HPE Helion OpenStack 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="venv-openstack-heat-x86_64-9.0.8~dev22-12.35.1" RelationType="Default Component Of" RelatesToProductReference="HPE Helion OpenStack 8">
      <FullProductName ProductID="HPE Helion OpenStack 8:venv-openstack-heat-x86_64-9.0.8~dev22-12.35.1">venv-openstack-heat-x86_64-9.0.8~dev22-12.35.1 as a component of HPE Helion OpenStack 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="venv-openstack-horizon-hpe-x86_64-12.0.5~dev6-14.38.1" RelationType="Default Component Of" RelatesToProductReference="HPE Helion OpenStack 8">
      <FullProductName ProductID="HPE Helion OpenStack 8:venv-openstack-horizon-hpe-x86_64-12.0.5~dev6-14.38.1">venv-openstack-horizon-hpe-x86_64-12.0.5~dev6-14.38.1 as a component of HPE Helion OpenStack 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="venv-openstack-monasca-x86_64-2.2.2~dev1-11.30.1" RelationType="Default Component Of" RelatesToProductReference="HPE Helion OpenStack 8">
      <FullProductName ProductID="HPE Helion OpenStack 8:venv-openstack-monasca-x86_64-2.2.2~dev1-11.30.1">venv-openstack-monasca-x86_64-2.2.2~dev1-11.30.1 as a component of HPE Helion OpenStack 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="ardana-ansible-8.0+git.1632499354.a56668f-3.82.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:ardana-ansible-8.0+git.1632499354.a56668f-3.82.1">ardana-ansible-8.0+git.1632499354.a56668f-3.82.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="ardana-monasca-8.0+git.1627997000.6c3bc04-3.30.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:ardana-monasca-8.0+git.1627997000.6c3bc04-3.30.1">ardana-monasca-8.0+git.1627997000.6c3bc04-3.30.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="documentation-suse-openstack-cloud-installation-8.20210806-1.35.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:documentation-suse-openstack-cloud-installation-8.20210806-1.35.1">documentation-suse-openstack-cloud-installation-8.20210806-1.35.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="documentation-suse-openstack-cloud-operations-8.20210806-1.35.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:documentation-suse-openstack-cloud-operations-8.20210806-1.35.1">documentation-suse-openstack-cloud-operations-8.20210806-1.35.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="documentation-suse-openstack-cloud-opsconsole-8.20210806-1.35.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:documentation-suse-openstack-cloud-opsconsole-8.20210806-1.35.1">documentation-suse-openstack-cloud-opsconsole-8.20210806-1.35.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="documentation-suse-openstack-cloud-planning-8.20210806-1.35.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:documentation-suse-openstack-cloud-planning-8.20210806-1.35.1">documentation-suse-openstack-cloud-planning-8.20210806-1.35.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="documentation-suse-openstack-cloud-security-8.20210806-1.35.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:documentation-suse-openstack-cloud-security-8.20210806-1.35.1">documentation-suse-openstack-cloud-security-8.20210806-1.35.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="documentation-suse-openstack-cloud-supplement-8.20210806-1.35.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:documentation-suse-openstack-cloud-supplement-8.20210806-1.35.1">documentation-suse-openstack-cloud-supplement-8.20210806-1.35.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="documentation-suse-openstack-cloud-upstream-admin-8.20210806-1.35.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:documentation-suse-openstack-cloud-upstream-admin-8.20210806-1.35.1">documentation-suse-openstack-cloud-upstream-admin-8.20210806-1.35.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="documentation-suse-openstack-cloud-upstream-user-8.20210806-1.35.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:documentation-suse-openstack-cloud-upstream-user-8.20210806-1.35.1">documentation-suse-openstack-cloud-upstream-user-8.20210806-1.35.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="documentation-suse-openstack-cloud-user-8.20210806-1.35.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:documentation-suse-openstack-cloud-user-8.20210806-1.35.1">documentation-suse-openstack-cloud-user-8.20210806-1.35.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="openstack-ec2-api-5.0.1~dev12-4.9.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:openstack-ec2-api-5.0.1~dev12-4.9.1">openstack-ec2-api-5.0.1~dev12-4.9.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="openstack-ec2-api-api-5.0.1~dev12-4.9.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:openstack-ec2-api-api-5.0.1~dev12-4.9.1">openstack-ec2-api-api-5.0.1~dev12-4.9.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="openstack-ec2-api-metadata-5.0.1~dev12-4.9.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:openstack-ec2-api-metadata-5.0.1~dev12-4.9.1">openstack-ec2-api-metadata-5.0.1~dev12-4.9.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="openstack-ec2-api-s3-5.0.1~dev12-4.9.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:openstack-ec2-api-s3-5.0.1~dev12-4.9.1">openstack-ec2-api-s3-5.0.1~dev12-4.9.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="openstack-heat-templates-0.0.0+git.1628179051.7d761bf-3.24.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:openstack-heat-templates-0.0.0+git.1628179051.7d761bf-3.24.1">openstack-heat-templates-0.0.0+git.1628179051.7d761bf-3.24.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-Django-1.11.29-3.28.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:python-Django-1.11.29-3.28.1">python-Django-1.11.29-3.28.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-ec2api-5.0.1~dev12-4.9.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:python-ec2api-5.0.1~dev12-4.9.1">python-ec2api-5.0.1~dev12-4.9.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-monasca-common-2.3.1~dev4-4.9.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:python-monasca-common-2.3.1~dev4-4.9.1">python-monasca-common-2.3.1~dev4-4.9.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="venv-openstack-heat-x86_64-9.0.8~dev22-12.35.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:venv-openstack-heat-x86_64-9.0.8~dev22-12.35.1">venv-openstack-heat-x86_64-9.0.8~dev22-12.35.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="venv-openstack-horizon-x86_64-12.0.5~dev6-14.38.2" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:venv-openstack-horizon-x86_64-12.0.5~dev6-14.38.2">venv-openstack-horizon-x86_64-12.0.5~dev6-14.38.2 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="venv-openstack-monasca-x86_64-2.2.2~dev1-11.30.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:venv-openstack-monasca-x86_64-2.2.2~dev1-11.30.1">venv-openstack-monasca-x86_64-2.2.2~dev1-11.30.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="documentation-suse-openstack-cloud-deployment-8.20210806-1.35.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 8">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 8:documentation-suse-openstack-cloud-deployment-8.20210806-1.35.1">documentation-suse-openstack-cloud-deployment-8.20210806-1.35.1 as a component of SUSE OpenStack Cloud Crowbar 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="documentation-suse-openstack-cloud-supplement-8.20210806-1.35.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 8">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 8:documentation-suse-openstack-cloud-supplement-8.20210806-1.35.1">documentation-suse-openstack-cloud-supplement-8.20210806-1.35.1 as a component of SUSE OpenStack Cloud Crowbar 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="documentation-suse-openstack-cloud-upstream-admin-8.20210806-1.35.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 8">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 8:documentation-suse-openstack-cloud-upstream-admin-8.20210806-1.35.1">documentation-suse-openstack-cloud-upstream-admin-8.20210806-1.35.1 as a component of SUSE OpenStack Cloud Crowbar 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="documentation-suse-openstack-cloud-upstream-user-8.20210806-1.35.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 8">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 8:documentation-suse-openstack-cloud-upstream-user-8.20210806-1.35.1">documentation-suse-openstack-cloud-upstream-user-8.20210806-1.35.1 as a component of SUSE OpenStack Cloud Crowbar 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="openstack-ec2-api-5.0.1~dev12-4.9.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 8">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 8:openstack-ec2-api-5.0.1~dev12-4.9.1">openstack-ec2-api-5.0.1~dev12-4.9.1 as a component of SUSE OpenStack Cloud Crowbar 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="openstack-ec2-api-api-5.0.1~dev12-4.9.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 8">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 8:openstack-ec2-api-api-5.0.1~dev12-4.9.1">openstack-ec2-api-api-5.0.1~dev12-4.9.1 as a component of SUSE OpenStack Cloud Crowbar 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="openstack-ec2-api-metadata-5.0.1~dev12-4.9.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 8">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 8:openstack-ec2-api-metadata-5.0.1~dev12-4.9.1">openstack-ec2-api-metadata-5.0.1~dev12-4.9.1 as a component of SUSE OpenStack Cloud Crowbar 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="openstack-ec2-api-s3-5.0.1~dev12-4.9.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 8">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 8:openstack-ec2-api-s3-5.0.1~dev12-4.9.1">openstack-ec2-api-s3-5.0.1~dev12-4.9.1 as a component of SUSE OpenStack Cloud Crowbar 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="openstack-heat-templates-0.0.0+git.1628179051.7d761bf-3.24.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 8">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 8:openstack-heat-templates-0.0.0+git.1628179051.7d761bf-3.24.1">openstack-heat-templates-0.0.0+git.1628179051.7d761bf-3.24.1 as a component of SUSE OpenStack Cloud Crowbar 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-Django-1.11.29-3.28.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 8">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 8:python-Django-1.11.29-3.28.1">python-Django-1.11.29-3.28.1 as a component of SUSE OpenStack Cloud Crowbar 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-ec2api-5.0.1~dev12-4.9.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 8">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 8:python-ec2api-5.0.1~dev12-4.9.1">python-ec2api-5.0.1~dev12-4.9.1 as a component of SUSE OpenStack Cloud Crowbar 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-monasca-common-2.3.1~dev4-4.9.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 8">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 8:python-monasca-common-2.3.1~dev4-4.9.1">python-monasca-common-2.3.1~dev4-4.9.1 as a component of SUSE OpenStack Cloud Crowbar 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.1-rubygem-puma-2.16.0-3.15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 8">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 8:ruby2.1-rubygem-puma-2.16.0-3.15.1">ruby2.1-rubygem-puma-2.16.0-3.15.1 as a component of SUSE OpenStack Cloud Crowbar 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.1-rubygem-redcarpet-3.2.3-3.3.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 8">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 8:ruby2.1-rubygem-redcarpet-3.2.3-3.3.1">ruby2.1-rubygem-redcarpet-3.2.3-3.3.1 as a component of SUSE OpenStack Cloud Crowbar 8</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the `:escape_html` option was being used. This is fixed in version 3.5.1 by the referenced commit.</Note>
    </Notes>
    <CVE>CVE-2020-26298</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>HPE Helion OpenStack 8:ardana-ansible-8.0+git.1632499354.a56668f-3.82.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:ardana-monasca-8.0+git.1627997000.6c3bc04-3.30.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:documentation-hpe-helion-openstack-installation-8.20210806-1.35.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:documentation-hpe-helion-openstack-operations-8.20210806-1.35.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:documentation-hpe-helion-openstack-opsconsole-8.20210806-1.35.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:documentation-hpe-helion-openstack-planning-8.20210806-1.35.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:documentation-hpe-helion-openstack-security-8.20210806-1.35.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:documentation-hpe-helion-openstack-user-8.20210806-1.35.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:openstack-ec2-api-5.0.1~dev12-4.9.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:openstack-ec2-api-api-5.0.1~dev12-4.9.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:openstack-ec2-api-metadata-5.0.1~dev12-4.9.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:openstack-ec2-api-s3-5.0.1~dev12-4.9.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:openstack-heat-templates-0.0.0+git.1628179051.7d761bf-3.24.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:python-Django-1.11.29-3.28.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:python-ec2api-5.0.1~dev12-4.9.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:python-monasca-common-2.3.1~dev4-4.9.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:venv-openstack-heat-x86_64-9.0.8~dev22-12.35.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:venv-openstack-horizon-hpe-x86_64-12.0.5~dev6-14.38.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:venv-openstack-monasca-x86_64-2.2.2~dev1-11.30.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:ardana-ansible-8.0+git.1632499354.a56668f-3.82.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:ardana-monasca-8.0+git.1627997000.6c3bc04-3.30.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:documentation-suse-openstack-cloud-installation-8.20210806-1.35.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:documentation-suse-openstack-cloud-operations-8.20210806-1.35.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:documentation-suse-openstack-cloud-opsconsole-8.20210806-1.35.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:documentation-suse-openstack-cloud-planning-8.20210806-1.35.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:documentation-suse-openstack-cloud-security-8.20210806-1.35.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:documentation-suse-openstack-cloud-supplement-8.20210806-1.35.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:documentation-suse-openstack-cloud-upstream-admin-8.20210806-1.35.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:documentation-suse-openstack-cloud-upstream-user-8.20210806-1.35.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:documentation-suse-openstack-cloud-user-8.20210806-1.35.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:openstack-ec2-api-5.0.1~dev12-4.9.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:openstack-ec2-api-api-5.0.1~dev12-4.9.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:openstack-ec2-api-metadata-5.0.1~dev12-4.9.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:openstack-ec2-api-s3-5.0.1~dev12-4.9.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:openstack-heat-templates-0.0.0+git.1628179051.7d761bf-3.24.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:python-Django-1.11.29-3.28.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:python-ec2api-5.0.1~dev12-4.9.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:python-monasca-common-2.3.1~dev4-4.9.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:venv-openstack-heat-x86_64-9.0.8~dev22-12.35.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:venv-openstack-horizon-x86_64-12.0.5~dev6-14.38.2</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:venv-openstack-monasca-x86_64-2.2.2~dev1-11.30.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:documentation-suse-openstack-cloud-deployment-8.20210806-1.35.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:documentation-suse-openstack-cloud-supplement-8.20210806-1.35.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:documentation-suse-openstack-cloud-upstream-admin-8.20210806-1.35.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:documentation-suse-openstack-cloud-upstream-user-8.20210806-1.35.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:openstack-ec2-api-5.0.1~dev12-4.9.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:openstack-ec2-api-api-5.0.1~dev12-4.9.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:openstack-ec2-api-metadata-5.0.1~dev12-4.9.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:openstack-ec2-api-s3-5.0.1~dev12-4.9.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:openstack-heat-templates-0.0.0+git.1628179051.7d761bf-3.24.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:python-Django-1.11.29-3.28.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:python-ec2api-5.0.1~dev12-4.9.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:python-monasca-common-2.3.1~dev4-4.9.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:ruby2.1-rubygem-puma-2.16.0-3.15.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:ruby2.1-rubygem-redcarpet-3.2.3-3.3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>3.5</BaseScore>
        <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20213728-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-26298.html</URL>
        <Description>CVE-2020-26298</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1180837</URL>
        <Description>SUSE Bug 1180837</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Puma is a HTTP 1.1 server for Ruby/Rack applications. Prior to versions 5.5.1 and 4.3.9, using `puma` with a proxy which forwards HTTP header values which contain the LF character could allow HTTP request smugggling. A client could smuggle a request through a proxy, causing the proxy to send a response back to another unknown client. The only proxy which has this behavior, as far as the Puma team is aware of, is Apache Traffic Server. If the proxy uses persistent connections and the client adds another request in via HTTP pipelining, the proxy may mistake it as the first request's body. Puma, however, would see it as two requests, and when processing the second request, send back a response that the proxy does not expect. If the proxy has reused the persistent connection to Puma to send another request for a different client, the second response from the first client will be sent to the second client. This vulnerability was patched in Puma 5.5.1 and 4.3.9. As a workaround, do not use Apache Traffic Server with `puma`.</Note>
    </Notes>
    <CVE>CVE-2021-41136</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>HPE Helion OpenStack 8:ardana-ansible-8.0+git.1632499354.a56668f-3.82.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:ardana-monasca-8.0+git.1627997000.6c3bc04-3.30.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:documentation-hpe-helion-openstack-installation-8.20210806-1.35.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:documentation-hpe-helion-openstack-operations-8.20210806-1.35.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:documentation-hpe-helion-openstack-opsconsole-8.20210806-1.35.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:documentation-hpe-helion-openstack-planning-8.20210806-1.35.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:documentation-hpe-helion-openstack-security-8.20210806-1.35.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:documentation-hpe-helion-openstack-user-8.20210806-1.35.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:openstack-ec2-api-5.0.1~dev12-4.9.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:openstack-ec2-api-api-5.0.1~dev12-4.9.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:openstack-ec2-api-metadata-5.0.1~dev12-4.9.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:openstack-ec2-api-s3-5.0.1~dev12-4.9.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:openstack-heat-templates-0.0.0+git.1628179051.7d761bf-3.24.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:python-Django-1.11.29-3.28.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:python-ec2api-5.0.1~dev12-4.9.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:python-monasca-common-2.3.1~dev4-4.9.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:venv-openstack-heat-x86_64-9.0.8~dev22-12.35.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:venv-openstack-horizon-hpe-x86_64-12.0.5~dev6-14.38.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:venv-openstack-monasca-x86_64-2.2.2~dev1-11.30.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:ardana-ansible-8.0+git.1632499354.a56668f-3.82.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:ardana-monasca-8.0+git.1627997000.6c3bc04-3.30.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:documentation-suse-openstack-cloud-installation-8.20210806-1.35.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:documentation-suse-openstack-cloud-operations-8.20210806-1.35.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:documentation-suse-openstack-cloud-opsconsole-8.20210806-1.35.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:documentation-suse-openstack-cloud-planning-8.20210806-1.35.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:documentation-suse-openstack-cloud-security-8.20210806-1.35.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:documentation-suse-openstack-cloud-supplement-8.20210806-1.35.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:documentation-suse-openstack-cloud-upstream-admin-8.20210806-1.35.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:documentation-suse-openstack-cloud-upstream-user-8.20210806-1.35.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:documentation-suse-openstack-cloud-user-8.20210806-1.35.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:openstack-ec2-api-5.0.1~dev12-4.9.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:openstack-ec2-api-api-5.0.1~dev12-4.9.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:openstack-ec2-api-metadata-5.0.1~dev12-4.9.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:openstack-ec2-api-s3-5.0.1~dev12-4.9.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:openstack-heat-templates-0.0.0+git.1628179051.7d761bf-3.24.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:python-Django-1.11.29-3.28.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:python-ec2api-5.0.1~dev12-4.9.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:python-monasca-common-2.3.1~dev4-4.9.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:venv-openstack-heat-x86_64-9.0.8~dev22-12.35.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:venv-openstack-horizon-x86_64-12.0.5~dev6-14.38.2</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:venv-openstack-monasca-x86_64-2.2.2~dev1-11.30.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:documentation-suse-openstack-cloud-deployment-8.20210806-1.35.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:documentation-suse-openstack-cloud-supplement-8.20210806-1.35.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:documentation-suse-openstack-cloud-upstream-admin-8.20210806-1.35.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:documentation-suse-openstack-cloud-upstream-user-8.20210806-1.35.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:openstack-ec2-api-5.0.1~dev12-4.9.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:openstack-ec2-api-api-5.0.1~dev12-4.9.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:openstack-ec2-api-metadata-5.0.1~dev12-4.9.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:openstack-ec2-api-s3-5.0.1~dev12-4.9.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:openstack-heat-templates-0.0.0+git.1628179051.7d761bf-3.24.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:python-Django-1.11.29-3.28.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:python-ec2api-5.0.1~dev12-4.9.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:python-monasca-common-2.3.1~dev4-4.9.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:ruby2.1-rubygem-puma-2.16.0-3.15.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:ruby2.1-rubygem-redcarpet-3.2.3-3.3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>3.6</BaseScore>
        <Vector>AV:N/AC:H/Au:S/C:P/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20213728-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-41136.html</URL>
        <Description>CVE-2021-41136</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1191681</URL>
        <Description>SUSE Bug 1191681</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
