Re: [Openstack] OpenStack CVE Wiki page

2013-06-05 Thread Jolyon Brown
Hi Thierry Thanks for the response. >So in summary... yes this is currently harder than it should be and I'd >like to fix that. Yes you're welcome to edit [1] so that it's made more >current. If you think it has value I can retroactively mention past >OSSAs in [2]. And you should have a look at [

Re: [Openstack] OpenStack CVE Wiki page

2013-06-05 Thread Thierry Carrez
Jolyon Brown wrote: > In my (day) job (not Limilo!) we're currently evaluating an IBM product > which is underpinned by OpenStack. During review our InfoSec people > claimed many (22) open CVE vulnerabilities for the underlying version of > OpenStack used (Folsom). I don't believe this to be the ca