Activity log for bug #1586079

Date Who What changed Old value New value Message
2016-05-26 15:15:40 Kirill Zaitsev bug added bug
2016-05-26 17:36:21 Serg Melikyan bug added subscriber Victor Ryzhenkin
2016-05-26 18:52:42 Serg Melikyan nominated for series murano/newton
2016-05-26 18:52:42 Serg Melikyan bug task added murano/newton
2016-05-26 18:52:42 Serg Melikyan nominated for series murano/kilo
2016-05-26 18:52:42 Serg Melikyan bug task added murano/kilo
2016-05-26 18:52:42 Serg Melikyan nominated for series murano/liberty
2016-05-26 18:52:42 Serg Melikyan bug task added murano/liberty
2016-05-26 18:52:42 Serg Melikyan nominated for series murano/mitaka
2016-05-26 18:52:42 Serg Melikyan bug task added murano/mitaka
2016-05-26 19:20:38 Serg Melikyan murano/newton: assignee Kirill Zaitsev (kzaitsev)
2016-05-26 19:25:28 Serg Melikyan description YaqlYamlLoader inherits from YamlLoader, meaning that it is possible to use extended unsafe tags in yaml files http://pyyaml.org/wiki/PyYAMLDocumentation#YAMLtagsandPythontypes Both dashboard, engine/api seem to be vulnerable. This issue is being treated as a potential security risk under embargo. Please do not make any public mention of embargoed (private) security vulnerabilities before their coordinated publication by the OpenStack Vulnerability Management Team in the form of an official OpenStack Security Advisory. This includes discussion of the bug or associated fixes in public forums such as mailing lists, code review systems and bug trackers. Please also avoid private disclosure to other individuals not already approved for access to this information, and provide this same reminder to those who are made aware of the issue prior to publication. All discussion should remain confined to this private bug report, and any proposed fixes should be added to the bug as attachments. ------------------------------------------------------------------------- YaqlYamlLoader inherits from YamlLoader, meaning that it is possible to use extended unsafe tags in yaml files http://pyyaml.org/wiki/PyYAMLDocumentation#YAMLtagsandPythontypes Both dashboard, engine/api seem to be vulnerable.
2016-05-26 20:46:28 Victor Ryzhenkin bug added subscriber Grant Murphy
2016-05-26 20:47:02 Victor Ryzhenkin bug added subscriber Tristan Cacqueray
2016-05-26 21:22:43 Kirill Zaitsev attachment added dashboard.patch https://bugs.launchpad.net/murano/+bug/1586079/+attachment/4670938/+files/dashboard.patch
2016-05-26 21:31:40 Kirill Zaitsev attachment removed dashboard.patch https://bugs.launchpad.net/murano/+bug/1586079/+attachment/4670938/+files/dashboard.patch
2016-05-26 21:32:09 Kirill Zaitsev attachment added dashboard part https://bugs.launchpad.net/murano/+bug/1586079/+attachment/4670940/+files/dashboard.patch
2016-05-26 21:47:51 Kirill Zaitsev attachment added murano.patch https://bugs.launchpad.net/murano/+bug/1586079/+attachment/4670941/+files/murano.patch
2016-05-27 12:38:26 Kirill Zaitsev bug added subscriber Stan Lagun
2016-05-27 12:40:31 Kirill Zaitsev bug added subscriber Nikolay Starodubtsev
2016-05-27 14:06:11 Serg Melikyan bug added subscriber Alexander Tivelkov
2016-05-27 14:14:35 Kirill Zaitsev murano/mitaka: status New Confirmed
2016-05-27 14:14:37 Kirill Zaitsev murano/liberty: status New Confirmed
2016-05-27 14:14:39 Kirill Zaitsev murano/kilo: status New Confirmed
2016-05-27 14:16:08 Kirill Zaitsev attachment added dashboard-mitaka.patch https://bugs.launchpad.net/murano/+bug/1586079/+attachment/4671302/+files/dashboard-mitaka.patch
2016-05-27 14:16:22 Kirill Zaitsev attachment added dashboard-liberty.patch https://bugs.launchpad.net/murano/+bug/1586079/+attachment/4671303/+files/dashboard-liberty.patch
2016-05-27 14:16:38 Kirill Zaitsev attachment added dashboard-kilo.patch https://bugs.launchpad.net/murano/+bug/1586079/+attachment/4671304/+files/dashboard-kilo.patch
2016-05-27 14:27:24 Serg Melikyan bug added subscriber Igor Marnat
2016-05-27 16:03:37 Kirill Zaitsev attachment added murano-mitaka.patch https://bugs.launchpad.net/murano/+bug/1586079/+attachment/4671407/+files/murano-mitaka.patch
2016-05-27 16:03:48 Kirill Zaitsev attachment added murano-liberty.patch https://bugs.launchpad.net/murano/+bug/1586079/+attachment/4671408/+files/murano-liberty.patch
2016-05-27 16:04:08 Kirill Zaitsev attachment added murano-kilo.patch https://bugs.launchpad.net/murano/+bug/1586079/+attachment/4671409/+files/murano-kilo.patch
2016-05-27 18:11:08 Kirill Zaitsev murano/mitaka: milestone 2.0.x
2016-05-27 18:11:10 Kirill Zaitsev murano/liberty: milestone 1.0.x
2016-05-30 16:05:16 Kirill Zaitsev attachment removed murano.patch https://bugs.launchpad.net/murano/+bug/1586079/+attachment/4670941/+files/murano.patch
2016-05-30 16:05:27 Kirill Zaitsev attachment removed murano-mitaka.patch https://bugs.launchpad.net/murano/+bug/1586079/+attachment/4671407/+files/murano-mitaka.patch
2016-05-30 16:05:32 Kirill Zaitsev attachment removed murano-liberty.patch https://bugs.launchpad.net/murano/+bug/1586079/+attachment/4671408/+files/murano-liberty.patch
2016-05-30 16:05:37 Kirill Zaitsev attachment removed murano-kilo.patch https://bugs.launchpad.net/murano/+bug/1586079/+attachment/4671409/+files/murano-kilo.patch
2016-05-30 16:06:30 Kirill Zaitsev attachment added murano.patch https://bugs.launchpad.net/murano/+bug/1586079/+attachment/4673061/+files/murano.patch
2016-05-30 16:06:40 Kirill Zaitsev attachment added murano-mitaka.patch https://bugs.launchpad.net/murano/+bug/1586079/+attachment/4673062/+files/murano-mitaka.patch
2016-05-30 16:06:49 Kirill Zaitsev attachment added murano-liberty.patch https://bugs.launchpad.net/murano/+bug/1586079/+attachment/4673063/+files/murano-liberty.patch
2016-05-30 16:06:58 Kirill Zaitsev attachment added murano-kilo.patch https://bugs.launchpad.net/murano/+bug/1586079/+attachment/4673064/+files/murano-kilo.patch
2016-06-15 15:39:59 Kirill Zaitsev murano: milestone newton-1 newton-2
2016-06-15 22:19:18 Kirill Zaitsev murano/kilo: status Confirmed Won't Fix
2016-06-15 22:29:01 Kirill Zaitsev cve linked 2016-4972
2016-06-23 16:03:41 Kirill Zaitsev information type Private Security Public Security
2016-06-23 16:09:31 Kirill Zaitsev murano/mitaka: importance Undecided Critical
2016-06-23 16:09:33 Kirill Zaitsev murano/liberty: importance Undecided Critical
2016-06-23 16:09:36 Kirill Zaitsev murano/kilo: importance Undecided Critical
2016-06-23 16:09:38 Kirill Zaitsev murano/newton: status Confirmed In Progress
2016-06-23 16:09:39 Kirill Zaitsev murano/mitaka: status Confirmed In Progress
2016-06-23 16:09:42 Kirill Zaitsev murano/liberty: status Confirmed In Progress
2016-06-23 16:50:21 OpenStack Infra murano: status In Progress Fix Released
2016-06-23 17:25:11 OpenStack Infra murano/mitaka: status In Progress Fix Committed
2016-06-23 17:25:17 OpenStack Infra murano/liberty: status In Progress Fix Committed
2016-06-24 15:33:02 Kirill Zaitsev description This issue is being treated as a potential security risk under embargo. Please do not make any public mention of embargoed (private) security vulnerabilities before their coordinated publication by the OpenStack Vulnerability Management Team in the form of an official OpenStack Security Advisory. This includes discussion of the bug or associated fixes in public forums such as mailing lists, code review systems and bug trackers. Please also avoid private disclosure to other individuals not already approved for access to this information, and provide this same reminder to those who are made aware of the issue prior to publication. All discussion should remain confined to this private bug report, and any proposed fixes should be added to the bug as attachments. ------------------------------------------------------------------------- YaqlYamlLoader inherits from YamlLoader, meaning that it is possible to use extended unsafe tags in yaml files http://pyyaml.org/wiki/PyYAMLDocumentation#YAMLtagsandPythontypes Both dashboard, engine/api seem to be vulnerable. YaqlYamlLoader inherits from YamlLoader, meaning that it is possible to use extended unsafe tags in yaml files http://pyyaml.org/wiki/PyYAMLDocumentation#YAMLtagsandPythontypes Both dashboard, engine/api seem to be vulnerable.
2016-06-24 15:34:03 Kirill Zaitsev murano/mitaka: assignee Kirill Zaitsev (kzaitsev)
2016-06-24 15:34:07 Kirill Zaitsev murano/kilo: assignee Kirill Zaitsev (kzaitsev)
2016-06-24 15:34:09 Kirill Zaitsev murano/liberty: assignee Kirill Zaitsev (kzaitsev)
2016-06-24 15:34:21 Kirill Zaitsev murano/kilo: assignee Kirill Zaitsev (kzaitsev)
2016-07-01 13:35:00 Kirill Zaitsev murano/liberty: status Fix Committed Fix Released
2016-07-01 13:35:01 Kirill Zaitsev murano/mitaka: status Fix Committed Fix Released