[Openstack] OpenStack CVE Wiki page

2013-06-05 Thread Jolyon Brown
Hi All Wasn't sure which list to address this to (possibly documentation?), please feel free to redirect me! In my (day) job (not Limilo!) we're currently evaluating an IBM product which is underpinned by OpenStack. During review our InfoSec people claimed many (22) open CVE vulnerabilities for

Re: [Openstack] OpenStack CVE Wiki page

2013-06-05 Thread Thierry Carrez
Jolyon Brown wrote: In my (day) job (not Limilo!) we're currently evaluating an IBM product which is underpinned by OpenStack. During review our InfoSec people claimed many (22) open CVE vulnerabilities for the underlying version of OpenStack used (Folsom). I don't believe this to be the case,

Re: [Openstack] OpenStack CVE Wiki page

2013-06-05 Thread Jolyon Brown
Hi Thierry Thanks for the response. So in summary... yes this is currently harder than it should be and I'd like to fix that. Yes you're welcome to edit [1] so that it's made more current. If you think it has value I can retroactively mention past OSSAs in [2]. And you should have a look at [3]