USN-2208-1: OpenStack Cinder vulnerability
6 May 2014
OpenStack Cinder could be made to expose sensitive information over the network.
- cinder - OpenStack storage service
JuanFra Rodriguez Cardoso discovered that OpenStack Cinder did not enforce
SSL connections when Nova was configured to use QPid and qpid_protocol is
set to 'ssl'. If a remote attacker were able to perform a machine-in-the-middle
attack, this flaw could be exploited to view sensitive information. Ubuntu
does not use QPid with Nova by default.
- USN-2247-1: nova-baremetal, nova-volume, nova-compute-xen, nova-novncproxy, python-nova, nova-common, nova-conductor, nova-scheduler, nova-compute-vmware, nova-api-os-volume, nova-objectstore, nova-network, nova-api-metadata, nova-compute-lxc, nova-cells, nova-compute, nova-xvpvncproxy, nova-cert, nova-ajax-console-proxy, nova-consoleauth, nova-spiceproxy, nova-api-os-compute, nova-doc, nova-compute-libvirt, nova-api-ec2, nova-api, nova, nova-compute-kvm, nova-compute-qemu, nova-console
- USN-2208-2: python-quantum, quantum