From 698b261a5a2a6c0f31ef5059046ef7196d5cba30 Mon Sep 17 00:00:00 2001 From: Matt Riedemann Date: Tue, 14 Nov 2017 15:01:52 -0500 Subject: [PATCH] Add security release note for OSSA-2017-005 Change-Id: I053f1bbc56481bddce8792aa4b5460a55cc0db2d Related-Bug: #1664931 (cherry picked from commit 31d28eef95ab82bdfce2221cd5633bcf4bc13653) (cherry picked from commit 3f63d057a64b688b66ff1903c1afc4d97ba6df6d) (cherry picked from commit ffd4f72d16dacd6ca1e703f9bab37b8917d253e7) --- ...931-validate-image-rebuild-9c5b05a001c94a4d.yaml | 13 +++++++++++++ 1 file changed, 13 insertions(+) create mode 100644 releasenotes/notes/bug-1664931-validate-image-rebuild-9c5b05a001c94a4d.yaml diff --git a/releasenotes/notes/bug-1664931-validate-image-rebuild-9c5b05a001c94a4d.yaml b/releasenotes/notes/bug-1664931-validate-image-rebuild-9c5b05a001c94a4d.yaml new file mode 100644 index 000000000000..675debe44a6a --- /dev/null +++ b/releasenotes/notes/bug-1664931-validate-image-rebuild-9c5b05a001c94a4d.yaml @@ -0,0 +1,13 @@ +--- +security: + - | + `OSSA-2017-005`_: Nova Filter Scheduler bypass through rebuild action + + By rebuilding an instance, an authenticated user may be able to circumvent + the FilterScheduler bypassing imposed filters (for example, the + ImagePropertiesFilter or the IsolatedHostsFilter). All setups using the + FilterScheduler (or CachingScheduler) are affected. + + The fix is in the `nova-api` and `nova-conductor` services. + + .. _OSSA-2017-005: https://security.openstack.org/ossa/OSSA-2017-005.html \ No newline at end of file