summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorMatt Riedemann <mriedem.os@gmail.com>2017-11-14 15:01:52 -0500
committerMatt Riedemann <mriedem.os@gmail.com>2017-11-14 15:51:21 -0500
commitffd4f72d16dacd6ca1e703f9bab37b8917d253e7 (patch)
tree260218d065e8668ee30930145167a7b7af8c0ce4
parent0944b77e6d174a9c4186c8b288c3dcb8a6b6b0fc (diff)
Add security release note for OSSA-2017-00515.0.8
Notes
Notes (review): Code-Review+2: Dan Smith <dms@danplanet.com> Code-Review+2: Tony Breeds <tony@bakeyournoodle.com> Workflow+1: Tony Breeds <tony@bakeyournoodle.com> Verified+2: Zuul Submitted-by: Zuul Submitted-at: Tue, 14 Nov 2017 22:20:32 +0000 Reviewed-on: https://review.openstack.org/519753 Project: openstack/nova Branch: refs/heads/stable/ocata
-rw-r--r--releasenotes/notes/bug-1664931-validate-image-rebuild-9c5b05a001c94a4d.yaml13
1 files changed, 13 insertions, 0 deletions
diff --git a/releasenotes/notes/bug-1664931-validate-image-rebuild-9c5b05a001c94a4d.yaml b/releasenotes/notes/bug-1664931-validate-image-rebuild-9c5b05a001c94a4d.yaml
new file mode 100644
index 0000000..675debe
--- /dev/null
+++ b/releasenotes/notes/bug-1664931-validate-image-rebuild-9c5b05a001c94a4d.yaml
@@ -0,0 +1,13 @@
1---
2security:
3 - |
4 `OSSA-2017-005`_: Nova Filter Scheduler bypass through rebuild action
5
6 By rebuilding an instance, an authenticated user may be able to circumvent
7 the FilterScheduler bypassing imposed filters (for example, the
8 ImagePropertiesFilter or the IsolatedHostsFilter). All setups using the
9 FilterScheduler (or CachingScheduler) are affected.
10
11 The fix is in the `nova-api` and `nova-conductor` services.
12
13 .. _OSSA-2017-005: https://security.openstack.org/ossa/OSSA-2017-005.html \ No newline at end of file