Upgrade to ansible 1.9.2 when released

Bug #1466216 reported by Ian Cordasco
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
OpenStack-Ansible
Fix Released
High
Tom Cameron
Kilo
Fix Released
High
Tom Cameron
Trunk
Fix Released
High
Tom Cameron

Bug Description

Ansible 1.9.2 (unreleased) fixed a CVE-2015-3908 that affected usage of get_url. The vulnerability is related to allowing an HTTPS connection to be MITM'd.

Tags: security

CVE References

Changed in openstack-ansible:
milestone: none → 11.0.4
Tom Cameron (drdabbles)
Changed in openstack-ansible:
assignee: nobody → Tom Cameron (tom-cameron)
Tom Cameron (drdabbles)
Changed in openstack-ansible:
status: Triaged → In Progress
Revision history for this message
Kevin Carter (kevin-carter) wrote :

Looks like 1.9.2-1 was just released, if we can get that in it would be most excellent.

Revision history for this message
Kevin Carter (kevin-carter) wrote :
Ian Cordasco (icordasc)
tags: added: security
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to os-ansible-deployment (kilo)

Fix proposed to branch: kilo
Review: https://review.openstack.org/196144

Changed in openstack-ansible:
status: In Progress → Fix Committed
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to os-ansible-deployment (kilo)

Reviewed: https://review.openstack.org/196144
Committed: https://git.openstack.org/cgit/stackforge/os-ansible-deployment/commit/?id=5514ae8878d787f63b24f980f204475524ec6644
Submitter: Jenkins
Branch: kilo

commit 5514ae8878d787f63b24f980f204475524ec6644
Author: Tom Cameron <email address hidden>
Date: Fri Jun 26 10:37:41 2015 -0400

    Upgrade to ansible 1.9.2

    Update Ansible version to v1.9.2-1. This update includes a fix to
    address CVE-2015-3908 - A vulnerability where HTTPS can be MITM'd.

    Change-Id: I4dca72706cf73cdd974788e9c012ad8ecb7a9c15
    Closes-Bug: #1466216
    (cherry picked from commit c22296272e4e299db7c12f5f9b4608737da13729)

Revision history for this message
Davanum Srinivas (DIMS) (dims-v) wrote : Fix included in openstack/openstack-ansible 11.2.11

This issue was fixed in the openstack/openstack-ansible 11.2.11 release.

Revision history for this message
Doug Hellmann (doug-hellmann) wrote : Fix included in openstack/openstack-ansible 11.2.12

This issue was fixed in the openstack/openstack-ansible 11.2.12 release.

Revision history for this message
Davanum Srinivas (DIMS) (dims-v) wrote : Fix included in openstack/openstack-ansible 11.2.14

This issue was fixed in the openstack/openstack-ansible 11.2.14 release.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.