2013-12-02 16:46:16 |
Steven Hardy |
bug |
|
|
added bug |
2013-12-02 16:46:33 |
Steven Hardy |
heat: status |
New |
In Progress |
|
2013-12-02 16:46:36 |
Steven Hardy |
heat: assignee |
|
Steven Hardy (shardy) |
|
2013-12-02 16:46:39 |
Steven Hardy |
heat: importance |
Undecided |
Critical |
|
2013-12-02 16:46:44 |
Steven Hardy |
heat: milestone |
|
icehouse-1 |
|
2013-12-02 16:46:55 |
Steven Hardy |
bug |
|
|
added subscriber Steve Baker |
2013-12-02 16:47:18 |
Steven Hardy |
bug |
|
|
added subscriber Steven Dake |
2013-12-02 16:47:44 |
Steven Hardy |
bug |
|
|
added subscriber Zane Bitter |
2013-12-02 16:50:49 |
Steven Hardy |
bug |
|
|
added subscriber Kurt Seifried |
2013-12-02 18:20:57 |
Kurt Seifried |
bug |
|
|
added subscriber Garth Mollett |
2013-12-02 19:09:05 |
Jeremy Stanley |
bug task added |
|
ossa |
|
2013-12-02 19:39:16 |
Jeremy Stanley |
ossa: status |
New |
Incomplete |
|
2013-12-02 22:27:16 |
Steve Baker |
tags |
|
grizzly-backport-potential havana-backport-potential |
|
2013-12-03 00:07:40 |
Steven Hardy |
attachment added |
|
Initial draft patch https://bugs.launchpad.net/heat/+bug/1256983/+attachment/3921741/+files/0001-Deny-API-requests-where-context-doesn-t-match-path.patch |
|
2013-12-03 11:52:43 |
Steven Hardy |
nominated for series |
|
heat/grizzly |
|
2013-12-03 11:52:43 |
Steven Hardy |
bug task added |
|
heat/grizzly |
|
2013-12-03 11:52:43 |
Steven Hardy |
nominated for series |
|
heat/havana |
|
2013-12-03 11:52:43 |
Steven Hardy |
bug task added |
|
heat/havana |
|
2013-12-03 11:52:50 |
Steven Hardy |
heat/grizzly: assignee |
|
Steven Hardy (shardy) |
|
2013-12-03 11:52:53 |
Steven Hardy |
heat/havana: assignee |
|
Steven Hardy (shardy) |
|
2013-12-03 11:52:57 |
Steven Hardy |
heat/grizzly: status |
New |
In Progress |
|
2013-12-03 11:53:00 |
Steven Hardy |
heat/havana: status |
New |
In Progress |
|
2013-12-03 11:53:04 |
Steven Hardy |
heat/grizzly: importance |
Undecided |
Critical |
|
2013-12-03 11:53:06 |
Steven Hardy |
heat/havana: importance |
Undecided |
Critical |
|
2013-12-03 11:54:13 |
Steven Hardy |
attachment added |
|
Proposed fix for master https://bugs.launchpad.net/heat/+bug/1256983/+attachment/3921984/+files/Master_0001-Deny-API-requests-where-context-doesn-t-match-path.patch |
|
2013-12-03 11:54:47 |
Steven Hardy |
attachment added |
|
Proposed fix for stable/havana https://bugs.launchpad.net/heat/+bug/1256983/+attachment/3921985/+files/Havana_0001-Deny-API-requests-where-context-doesn-t-match-path.patch |
|
2013-12-03 11:55:17 |
Steven Hardy |
attachment added |
|
Proposed fix for stable/grizzly https://bugs.launchpad.net/heat/+bug/1256983/+attachment/3921986/+files/Grizzly_0001-Deny-API-requests-where-context-doesn-t-match-path.patch |
|
2013-12-04 04:21:44 |
Steve Baker |
heat: milestone |
icehouse-1 |
icehouse-2 |
|
2013-12-04 21:01:56 |
Steve Baker |
heat: milestone |
icehouse-2 |
icehouse-1 |
|
2013-12-04 21:41:59 |
Thierry Carrez |
heat: milestone |
icehouse-1 |
icehouse-2 |
|
2013-12-04 21:42:03 |
Thierry Carrez |
heat/havana: milestone |
|
2013.2.1 |
|
2013-12-05 03:03:06 |
Jeremy Stanley |
ossa: status |
Incomplete |
Confirmed |
|
2013-12-05 03:03:09 |
Jeremy Stanley |
ossa: assignee |
|
Jeremy Stanley (fungi) |
|
2013-12-05 03:03:14 |
Jeremy Stanley |
ossa: importance |
Undecided |
Critical |
|
2013-12-06 01:10:44 |
Jeremy Stanley |
ossa: status |
Confirmed |
In Progress |
|
2013-12-06 03:00:53 |
Jeremy Stanley |
summary |
Heat ReST API doesn't respect tenant scoping |
Heat ReST API doesn't respect tenant scoping (CVE-2013-6428) |
|
2013-12-06 03:01:04 |
Jeremy Stanley |
cve linked |
|
2013-6428 |
|
2013-12-06 16:42:52 |
Jeremy Stanley |
ossa: status |
In Progress |
Fix Committed |
|
2013-12-06 16:43:01 |
Jeremy Stanley |
bug |
|
|
added subscriber Canonical Security Team |
2013-12-11 15:11:29 |
Jeremy Stanley |
information type |
Private Security |
Public Security |
|
2013-12-11 15:12:43 |
OpenStack Infra |
heat: assignee |
Steven Hardy (shardy) |
Jeremy Stanley (fungi) |
|
2013-12-11 15:13:52 |
Jeremy Stanley |
heat: assignee |
Jeremy Stanley (fungi) |
|
|
2013-12-11 15:14:40 |
OpenStack Infra |
heat/havana: assignee |
Steven Hardy (shardy) |
Jeremy Stanley (fungi) |
|
2013-12-11 15:15:11 |
Jeremy Stanley |
heat/havana: assignee |
Jeremy Stanley (fungi) |
|
|
2013-12-11 15:59:13 |
Jeremy Stanley |
summary |
Heat ReST API doesn't respect tenant scoping (CVE-2013-6428) |
[OSSA 2013-035] Heat ReST API doesn't respect tenant scoping (CVE-2013-6428) |
|
2013-12-11 16:44:46 |
OpenStack Infra |
heat: assignee |
|
Steven Hardy (shardy) |
|
2013-12-12 19:52:43 |
OpenStack Infra |
heat: status |
In Progress |
Fix Committed |
|
2013-12-14 19:09:38 |
OpenStack Infra |
heat/havana: status |
In Progress |
Fix Committed |
|
2013-12-14 19:10:15 |
Jeremy Stanley |
ossa: status |
Fix Committed |
Fix Released |
|
2013-12-16 23:10:34 |
Alan Pevec |
heat/havana: status |
Fix Committed |
Fix Released |
|
2014-01-22 16:10:00 |
Thierry Carrez |
heat: status |
Fix Committed |
Fix Released |
|
2014-03-31 12:30:41 |
Alan Pevec |
tags |
grizzly-backport-potential havana-backport-potential |
|
|
2014-03-31 12:31:05 |
Alan Pevec |
heat/grizzly: status |
In Progress |
Won't Fix |
|
2014-03-31 12:31:18 |
Alan Pevec |
heat/havana: assignee |
|
Steven Hardy (shardy) |
|
2014-04-17 10:14:48 |
Thierry Carrez |
heat: milestone |
icehouse-2 |
2014.1 |
|