[Yahoo-eng-team] [Bug 1511541] Re: Possible incomplete fix for OSSA-2015-005

2016-03-07 Thread Grant Murphy
Removed the OSSA task and marking invalid. ** Changed in: ossa Status: Incomplete => Invalid ** No longer affects: ossa ** Changed in: nova Status: Incomplete => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed

[Yahoo-eng-team] [Bug 1538061] Re: Ensure that LVM escapes instance names for device names correctly

2016-02-25 Thread Grant Murphy
Removed the OSSA task and opened the bug. Will leave it to the Nova PTL to close. ** Changed in: ossa Status: Incomplete => Won't Fix ** Information type changed from Private Security to Public ** No longer affects: ossa -- You received this bug notification because you are a member of

[Yahoo-eng-team] [Bug 1516765] Re: xenapi: volume_utils._parse_volume_info can leak connection password via StorageError (CVE-2015-8749)

2016-01-12 Thread Grant Murphy
** Changed in: ossa Status: In Progress => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Compute (nova). https://bugs.launchpad.net/bugs/1516765 Title: xenapi: volume_utils._parse_volume_info can

[Yahoo-eng-team] [Bug 1511541] [NEW] Possible incomplete fix for OSSA-2015-005

2015-10-29 Thread Grant Murphy
*** This bug is a security vulnerability *** Public security bug reported: Multiple reports that the fix for [OSSA 2015-005] Websocket Hijacking Vulnerability in Nova VNC Server (CVE-2015-0259) is incomplete. https://bugs.launchpad.net/nova/+bug/1409142/comments/146 https://bugs.launchpad.net/no

[Yahoo-eng-team] [Bug 1461734] Re: duplicate detach volume in nova

2015-08-03 Thread Grant Murphy
** Information type changed from Public Security to Public ** No longer affects: ossa -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Compute (nova). https://bugs.launchpad.net/bugs/1461734 Title: duplicate detach vol

[Yahoo-eng-team] [Bug 1464461] Re: delete action always cause error ( in kilo)

2015-07-13 Thread Grant Murphy
** Changed in: ossa Status: Incomplete => Won't Fix -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Dashboard (Horizon). https://bugs.launchpad.net/bugs/1464461 Title: delete action always cause error ( in kilo)

[Yahoo-eng-team] [Bug 1400966] Re: [OSSA-2014-041] Glance allows users to download and delete any file in glance-api server (CVE-2014-9493)

2015-01-07 Thread Grant Murphy
Reopening bug as fix was incomplete. Will request a new CVE id when a fix is ready. ** Changed in: glance Status: Fix Released => In Progress ** Changed in: glance Assignee: Zhi Yan Liu (lzy-dev) => Grant Murphy (gmurphy) ** Changed in: ossa Assignee: (unassigned) =&

[Yahoo-eng-team] [Bug 1400966] Re: [OSSA-2014-041] Glance allows users to download and delete any file in glance-api server (CVE-2014-9493)

2015-01-07 Thread Grant Murphy
** Changed in: ossa Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Glance. https://bugs.launchpad.net/bugs/1400966 Title: [OSSA-2014-041] Glance allows users to download and delete a

[Yahoo-eng-team] [Bug 1316822] Re: soft reboot of instance does not ensure iptables rules are present

2014-05-06 Thread Grant Murphy
Added OSSA bug task, set to incomplete until confirmed by core developer. Even then I suspect we might issue a OSSN instead of a OSSA for this. Thoughts? ** Also affects: ossa Importance: Undecided Status: New ** Changed in: ossa Status: New => Incomplete -- You received this

[Yahoo-eng-team] [Bug 1300274] Re: V3 Authentication Chaining - uniqueness of auth method names

2014-04-01 Thread Grant Murphy
** Also affects: ossa Importance: Undecided Status: New ** Information type changed from Public to Public Security -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1300274 Title:

[Yahoo-eng-team] [Bug 1243327] Re: [OSSA 2014-008] Routers can be cross plugged by other tenants (CVE-2014-0056)

2014-03-27 Thread Grant Murphy
** Changed in: ossa Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1243327 Title: [OSSA 2014-008] Routers can be cross plugged by other tenan

[Yahoo-eng-team] [Bug 1271426] Re: protected property change not rejected if a subsequent rule match accepts them

2014-02-10 Thread Grant Murphy
This seems like something that might catch out unsuspecting sysadmins. Do you think it is worth issuing an OSSN for this? ** Also affects: ossn Importance: Undecided Status: New -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscrib

[Yahoo-eng-team] [Bug 1257566] Re: EC2 and S3 token middleware create insecure connections

2013-12-03 Thread Grant Murphy
** Also affects: ossa Importance: Undecided Status: New -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1257566 Title: EC2 and S3 token middleware create insecure connections