web-download is subject to same port scan vulnerability as v1 copy_from

Bug #1748512 reported by Erno Kuvaja
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Glance
Fix Released
Critical
Erno Kuvaja

Bug Description

The feature is currently at parr with v1 copy_from which means https://bugs.launchpad.net/glance/+bug/1606495 does apply as well.

Erno Kuvaja (jokke)
Changed in glance:
importance: Undecided → Critical
assignee: nobody → Erno Kuvaja (jokke)
milestone: none → queens-rc2
Changed in glance:
status: New → In Progress
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to glance (master)

Reviewed: https://review.openstack.org/542956
Committed: https://git.openstack.org/cgit/openstack/glance/commit/?id=1591f573ae20037c8b87ca6c331e8e5ce4f77a0a
Submitter: Zuul
Branch: master

commit 1591f573ae20037c8b87ca6c331e8e5ce4f77a0a
Author: Erno Kuvaja <email address hidden>
Date: Fri Feb 9 13:18:19 2018 +0000

    URI filtering for web-download

    Implement URI filtering to prevent port scanning with the web-download
    Image import method.

    Closes-Bug: #1748512

    Change-Id: Ide5ace8979bb12239c99a312747b3151c1e64ce8

Changed in glance:
status: In Progress → Fix Released
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to glance (stable/queens)

Fix proposed to branch: stable/queens
Review: https://review.openstack.org/545097

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to glance (stable/queens)

Reviewed: https://review.openstack.org/545097
Committed: https://git.openstack.org/cgit/openstack/glance/commit/?id=51f47509190b5713fe9f3320ca3affba0c0d82bc
Submitter: Zuul
Branch: stable/queens

commit 51f47509190b5713fe9f3320ca3affba0c0d82bc
Author: Erno Kuvaja <email address hidden>
Date: Fri Feb 9 13:18:19 2018 +0000

    URI filtering for web-download

    Implement URI filtering to prevent port scanning with the web-download
    Image import method.

    Closes-Bug: #1748512

    Change-Id: Ide5ace8979bb12239c99a312747b3151c1e64ce8
    (cherry picked from commit 1591f573ae20037c8b87ca6c331e8e5ce4f77a0a)

tags: added: in-stable-queens
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix included in openstack/glance 16.0.0.0rc2

This issue was fixed in the openstack/glance 16.0.0.0rc2 release candidate.

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix included in openstack/glance 17.0.0.0b1

This issue was fixed in the openstack/glance 17.0.0.0b1 development milestone.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.