Commit Graph

30 Commits

Author SHA1 Message Date
OpenDev Sysadmins 428fd1bf7e OpenDev Migration Patch
This commit was bulk generated and pushed by the OpenDev sysadmins
as a part of the Git hosting and code review systems migration
detailed in these mailing list posts:

http://lists.openstack.org/pipermail/openstack-discuss/2019-March/003603.html
http://lists.openstack.org/pipermail/openstack-discuss/2019-April/004920.html

Attempts have been made to correct repository namespaces and
hostnames based on simple pattern matching, but it's possible some
were updated incorrectly or missed entirely. Please reach out to us
via the contact information listed at https://opendev.org/ with any
questions you may have.
2019-04-19 19:26:10 +00:00
Doug Chivers 39c8043bdf Nova networking IPtables rules not reinstated with soft reboot
Change-Id: Ib6158b24fbb4b1bbff328df664091f51a8013b95
Closes-Bug: 1316822
2014-08-07 19:01:06 +01:00
Nathan Kinder abb944a64d Remove wiki template
The wiki template has confused authors with regards to which
template they should use to author a new note.  Since the source
repository only contains notes in the "email" template format, we
should only contain that template here.  The wiki conversion can
be described on the OSSN process page instead.

Change-Id: I4a13ef98bcbcc8a49f14bf30096fb19b0afc8082
2014-07-25 14:33:51 -07:00
Nathan Kinder bf53cbc80a Corrected a simple typo in OSSN-0021
There was a simple typo in the recently merged version of OSSN-0021.
I caught and corrected it before publishing, but it should also be
corrected in tree.

Change-Id: Ib36b549cbc61ceecbaa2740181fcc35ef13c164c
2014-07-25 13:58:57 -07:00
Stanislaw Pitucha 9aaa0e77ad OSSN-0021 - Keystone trusts on compromised account
Adding a description of the issue of verifying Keystone trust in case
of account compromise. Including examples of API interaction to help
check the situation.

Closes-Bug: #1341849
Change-Id: Iaf38c214d553dfd4dfe29dac9dc1496c061fb765
2014-07-25 15:20:09 +01:00
Jenkins 78e62638d7 Merge "Adding OSSN-0019 - SSH Pool using auto-add policy." 2014-06-30 16:28:57 +00:00
Tim Kelsey e90df8f178 Adding OSSN-0019 - SSH Pool using auto-add policy.
Change-Id: I6ec9acdb6881bb4b7880d479fb3318be5f026015
2014-06-27 16:37:43 +01:00
Jenkins f17494ab48 Merge "Add OSSN-0018 - Dangerous network configuration" 2014-06-24 15:02:37 +00:00
tmcpeak e34b5c292b Adding OSSN-0017 - Session-fixation vulnerability in Horizon when using the default signed cookie sessions
OSSN-0017 describes an issue where the default setting in Horizon causes client side cookies to be used.
This allows an attacker who is able to capture a user's cookie to perform any action as that user, even
after that user has logged out.

Related-Bug: #1327425
Change-Id: I74bf8f308227c8adafc719474bec6f8cd1db2601
2014-06-18 13:44:23 -07:00
Stanislaw Pitucha c6d62a198a Add OSSN-0018 - Dangerous network configuration
Change-Id: Ic142853a238f30f4f50e2616a533637e8cb895ef
Related-Bug: 1316271
2014-06-18 17:10:54 +01:00
Nathan Kinder 5f5202470c Correct workaround in OSSN-0013
The workaround previously described in OSSN-0013 was not correct
due to a misunderstanding in the behavior of the original bug. This
update adds a workaround that has been tested in Havana, and it also
provides a more clear description about Glance's broken behavior
with regards to processing property protections rules.

Related-Bug: #1271426
Change-Id: Ice8f6d31345c308f09ee14b55053d205d9f57e69
2014-06-05 22:18:36 -07:00
Jenkins 29305c9fe5 Merge "Cinder secure wipe misconfiguration will result in no wipe, on Grizzly." 2014-06-02 18:29:43 +00:00
Doug Chivers 4f3db51563 Cinder secure wipe misconfiguration will result in no wipe, on
Grizzly.

DocImpact
Closes-Bug: #1322766

Change-Id: I27e3b321cd8b86dfae74c042a6642121184deb2f
2014-06-02 18:17:13 +01:00
Jenkins a4b7274e94 Merge "Add OSSN-0014 - Cinder drivers set insecure file permissions" 2014-05-31 00:32:37 +00:00
Nathan Kinder d342849a4a Add OSSN-0015 - Glance allows non-admin users to create public images
This adds OSSN-0015, which covers an issue related to Glance's default
policy allowing all users to publicize images. This can allow a user
to upload a malicious image in an attempt to attack other users.

Related-Bug: 1313746

Change-Id: Ida7519192a5b77730e4fffa7956978252a3d4c1e
2014-05-29 13:28:21 -07:00
Malini Bhandaru fd714a9be8 Add OSSN-0014 - Cinder drivers set insecure file permissions
This adds OSSN-0014, which covers the introduction of files with liberal
access permissions by multiple Cinder drivers in OpenStack Icehouse and
earlier. Users with access to the Cinder host and processes running
on the Cinder host can exploit the file permissions to disclose,
modify, and/or destroy user block storage data.

Closes-Bug: 1260679
Change-Id: I4ac9e746401051d85cb9cfbcad3c88b04f23106c
2014-05-29 11:59:35 -07:00
Robert Clark 407fb8f198 Adds OSSN-0013
This adds OSSN-0013 addressing an issue with the way Glance property
protections are processed. In some deployments it is possible that a
configuration will allow actions that the administrator had intended
to restrict, unless permissions are defined in a careful order.

Change-Id: Ib149f2559659702f21793c3394bd0791352e18b3
Closes-Bug: #1271426
2014-05-07 07:55:41 +01:00
Jenkins 3e3088b00d Merge "Add OSSN-0010 - Sample Keystone v3 policy exposes privilege escalation vulnerability" 2014-04-17 18:42:56 +00:00
Jamie Finnigan 1c3455cc2b Add OSSN-0010 - Sample Keystone v3 policy exposes privilege escalation
vulnerability

This adds OSSN-0010, which covers a privilege escalation issue
associated with a sample Keystone v3 policy file.

Change-Id: I3213bbf4b9956b75d733f219660fcefe6a51848d
Related-Bug: #1287219
2014-04-17 09:36:16 -07:00
Nathan Kinder c338a1fccc Correct typo in OSSN-0012 title
The title for OSSN-0012 has a misspelling in it.  This corrects
the typo.

Change-Id: Ic7c2a7f56d58986453a33b94f2d8b42efedcad05
2014-04-10 00:13:58 -07:00
Nathan Kinder 786d188b5d Add OSSN-0012 - OpenSSL Heartbleed vulnerability
This adds OSSN-0012, which covers the OpenSSL Heartbleed
vulnerability.  This isn't a vulnerability in OpenStack itself, but
OpenStack deployments are likely affected since they would be using
OpenSSL for SSL/TLS.

Change-Id: I2db43e23dc0b090887e937be6188b64e2a0a2ad5
2014-04-09 17:01:45 -07:00
Nathan Kinder f291579bfb Add OSSN-0011 - Heat templates with invalid references allows unintended network access
This adds OSSN-0011, which covers an issue related to invalid
security group references in CFN templates being improperly evaluated
by Heat.  This results in unintended network access being allowed.

Related-Bug: 1291091

Change-Id: I88ee23aadc74020f150332a619796ebd77ef9698
2014-04-04 15:18:26 -07:00
Jenkins 66136e3c69 Merge "Add gitreview file" 2014-04-02 17:02:16 +00:00
Nathan Kinder 5380798f05 Add OSSN-0009 - Potential token revocation abuse via group membership
This adds OSSN-0009, which covers an issue related to the ability
for a user to to abuse group operations in Keystone to trigger
revocation of tokens for other users.

Change-Id: Ic59048442a78fd37b4dcb608ee1a468af70fa82d
Related-Bug: #1268751
2014-04-01 19:48:58 -07:00
Nathan Kinder af9cfa77ce Add gitreview file
This adds a .gitreview file to allow one to easily add a gerrit
remote to a newly cloned repo by running 'git review -s'.

Change-Id: I019ec453f3cbcc07c9d51978c7c6bf87baf95f3f
2014-04-01 16:53:46 -07:00
Nathan Kinder 732ab7bec2 Add OSSN-0008 - DoS attack on noVNC/SPICE console due to lack of limiting
This adds OSSN-0008, which covers an issue related to the ability
for a user to exhaust the resources on a noVNC or SPICE console host
resulting in a DoS condition.
2014-03-09 09:58:57 -07:00
Nathan Kinder ce768e0d54 Modified templates to wrap lines at 72 characters
Some popular mail client PGP software will wrap lines at 72
characters.  If we send an OSSN out that has longer lines,
the formatting gets messed up.  This can make the OSSN hard
to read.  This patch modifies the templates to wrap lines at
72 characters so they match the guidelines posted in the OSSN
process pages on the wiki.

Now that we are publishing OSSNs on the wiki, I changed the
templates to include a link to the OSSN on the wiki instead
of duplicating the Launchpad link like we did previously.
2014-03-06 18:51:31 -08:00
Nathan Kinder 02a381f826 Add OSSN-0007 - unsecure libvirt live migration instructions
This adds OSSN-0007, which covers an issue related to securing
libvirt live migration.
2014-03-06 14:59:19 -08:00
Nathan Kinder f02609813e Add previously published security notes
This adds all previously published security notes to the repo.  I
also provided some helpful documentation in the README and provided
e-mail and wiki format templates to aid in writing new security
notes.
2014-02-12 21:35:18 -08:00
Nathan Kinder e5125edcbd Initial commit 2014-02-12 19:41:01 -08:00