Bug 1717133

Summary: add jsoncpp for dep of qpid-proton for fixing CVE-2019-0223
Product: Red Hat OpenStack Reporter: Jon Schlueter <jschluet>
Component: distributionAssignee: Jon Schlueter <jschluet>
Status: CLOSED ERRATA QA Contact: Leonid Natapov <lnatapov>
Severity: low Docs Contact:
Priority: low    
Version: 13.0 (Queens)CC: markmc
Target Milestone: asyncKeywords: TechPreview, Triaged, ZStream
Target Release: 13.0 (Queens)   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: jsoncpp-1.7.7-1.el7 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-06-06 15:55:23 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Jon Schlueter 2019-06-04 18:37:53 UTC
Description of problem:

qpid-proton-cpp sub-rpm in build that fixes CVE brings in new dependency.


This sub-rpm of qpid-proton is not installed or directly used by OpenStack or director installer.

Comment 5 Jon Schlueter 2019-06-04 18:54:05 UTC
to test for verification repo-closure has to pass.

Comment 10 Jon Schlueter 2019-06-04 21:00:08 UTC
with this included in advisory, TPS and repo-closure both clear.

Comment 11 Lon Hohberger 2019-06-04 21:05:17 UTC
Verified that available rpms are installable and satisfy the missing dependency introduced.

Comment 13 errata-xmlrpc 2019-06-06 15:55:23 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2019:1400