Activity log for bug #1586078

Date Who What changed Old value New value Message
2016-05-26 15:13:27 Kirill Zaitsev bug added bug
2016-05-26 17:36:30 Serg Melikyan bug added subscriber Victor Ryzhenkin
2016-05-26 19:20:49 Serg Melikyan python-muranoclient: assignee Kirill Zaitsev (kzaitsev)
2016-05-26 19:21:01 Serg Melikyan nominated for series python-muranoclient/liberty
2016-05-26 19:21:01 Serg Melikyan bug task added python-muranoclient/liberty
2016-05-26 19:21:01 Serg Melikyan nominated for series python-muranoclient/mitaka
2016-05-26 19:21:01 Serg Melikyan bug task added python-muranoclient/mitaka
2016-05-26 19:21:01 Serg Melikyan nominated for series python-muranoclient/0.5.x
2016-05-26 19:21:01 Serg Melikyan bug task added python-muranoclient/0.5.x
2016-05-26 19:21:01 Serg Melikyan nominated for series python-muranoclient/newton
2016-05-26 19:21:01 Serg Melikyan bug task added python-muranoclient/newton
2016-05-26 19:21:01 Serg Melikyan nominated for series python-muranoclient/kilo
2016-05-26 19:21:01 Serg Melikyan bug task added python-muranoclient/kilo
2016-05-26 19:21:14 Serg Melikyan bug task deleted python-muranoclient/0.5.x
2016-05-26 19:25:39 Serg Melikyan description YaqlYamlLoader inherits from YamlLoader, meaning that it is possible to use extended unsafe tags in yaml files http://pyyaml.org/wiki/PyYAMLDocumentation#YAMLtagsandPythontypes This issue is being treated as a potential security risk under embargo. Please do not make any public mention of embargoed (private) security vulnerabilities before their coordinated publication by the OpenStack Vulnerability Management Team in the form of an official OpenStack Security Advisory. This includes discussion of the bug or associated fixes in public forums such as mailing lists, code review systems and bug trackers. Please also avoid private disclosure to other individuals not already approved for access to this information, and provide this same reminder to those who are made aware of the issue prior to publication. All discussion should remain confined to this private bug report, and any proposed fixes should be added to the bug as attachments. ------------------------------------------------------------------------- YaqlYamlLoader inherits from YamlLoader, meaning that it is possible to use extended unsafe tags in yaml files http://pyyaml.org/wiki/PyYAMLDocumentation#YAMLtagsandPythontypes
2016-05-26 20:47:44 Victor Ryzhenkin tags security
2016-05-26 20:47:55 Victor Ryzhenkin bug added subscriber Tristan Cacqueray
2016-05-26 20:48:15 Victor Ryzhenkin bug added subscriber Grant Murphy
2016-05-26 22:14:09 Kirill Zaitsev attachment added client.patch https://bugs.launchpad.net/python-muranoclient/+bug/1586078/+attachment/4670952/+files/client.patch
2016-05-27 12:38:41 Kirill Zaitsev bug added subscriber Stan Lagun
2016-05-27 12:40:50 Kirill Zaitsev bug added subscriber Nikolay Starodubtsev
2016-05-27 13:54:39 Kirill Zaitsev attachment added client-mitaka.patch https://bugs.launchpad.net/python-muranoclient/+bug/1586078/+attachment/4671295/+files/client-mitaka.patch
2016-05-27 13:54:52 Kirill Zaitsev attachment added client-liberty.patch https://bugs.launchpad.net/python-muranoclient/+bug/1586078/+attachment/4671296/+files/client-liberty.patch
2016-05-27 13:55:06 Kirill Zaitsev attachment added client-kilo.patch https://bugs.launchpad.net/python-muranoclient/+bug/1586078/+attachment/4671297/+files/client-kilo.patch
2016-05-27 13:55:15 Kirill Zaitsev python-muranoclient/mitaka: status New Confirmed
2016-05-27 13:55:17 Kirill Zaitsev python-muranoclient/liberty: status New Confirmed
2016-05-27 13:55:19 Kirill Zaitsev python-muranoclient/kilo: status New Confirmed
2016-05-27 13:55:26 Kirill Zaitsev python-muranoclient/mitaka: milestone 0.8.5
2016-05-27 13:55:27 Kirill Zaitsev python-muranoclient/liberty: milestone 0.7.3
2016-05-27 13:55:29 Kirill Zaitsev python-muranoclient/kilo: milestone 0.5.10
2016-05-27 14:05:59 Serg Melikyan bug added subscriber Alexander Tivelkov
2016-05-27 14:27:32 Serg Melikyan bug added subscriber Igor Marnat
2016-06-15 22:29:22 Kirill Zaitsev cve linked 2016-4972
2016-06-23 16:03:38 Kirill Zaitsev information type Private Security Public Security
2016-06-23 16:03:49 Kirill Zaitsev python-muranoclient/kilo: status Confirmed Won't Fix
2016-06-23 16:10:50 Kirill Zaitsev python-muranoclient/mitaka: importance Undecided Critical
2016-06-23 16:10:53 Kirill Zaitsev python-muranoclient/liberty: status Confirmed In Progress
2016-06-23 16:10:54 Kirill Zaitsev python-muranoclient/liberty: importance Undecided Critical
2016-06-23 16:10:56 Kirill Zaitsev python-muranoclient/newton: status Confirmed In Progress
2016-06-23 16:10:59 Kirill Zaitsev python-muranoclient/mitaka: status Confirmed In Progress
2016-06-23 17:28:50 OpenStack Infra python-muranoclient: status In Progress Fix Released
2016-06-23 17:29:06 OpenStack Infra python-muranoclient/mitaka: status In Progress Fix Committed
2016-06-23 17:45:49 OpenStack Infra python-muranoclient/liberty: status In Progress Fix Committed
2016-06-24 15:33:33 Kirill Zaitsev description This issue is being treated as a potential security risk under embargo. Please do not make any public mention of embargoed (private) security vulnerabilities before their coordinated publication by the OpenStack Vulnerability Management Team in the form of an official OpenStack Security Advisory. This includes discussion of the bug or associated fixes in public forums such as mailing lists, code review systems and bug trackers. Please also avoid private disclosure to other individuals not already approved for access to this information, and provide this same reminder to those who are made aware of the issue prior to publication. All discussion should remain confined to this private bug report, and any proposed fixes should be added to the bug as attachments. ------------------------------------------------------------------------- YaqlYamlLoader inherits from YamlLoader, meaning that it is possible to use extended unsafe tags in yaml files http://pyyaml.org/wiki/PyYAMLDocumentation#YAMLtagsandPythontypes YaqlYamlLoader inherits from YamlLoader, meaning that it is possible to use extended unsafe tags in yaml files http://pyyaml.org/wiki/PyYAMLDocumentation#YAMLtagsandPythontypes
2016-06-24 15:33:44 Kirill Zaitsev python-muranoclient/mitaka: assignee Kirill Zaitsev (kzaitsev)
2016-06-24 15:33:46 Kirill Zaitsev python-muranoclient/liberty: assignee Kirill Zaitsev (kzaitsev)