Bug#827886: [PKG-Openstack-devel] Bug#827886: ironic: CVE-2016-4985: Ironic node information including credentials exposed to unathenticated users

2016-06-22 Thread Salvatore Bonaccorso
Hi Thomas, On Wed, Jun 22, 2016 at 11:17:44AM +0200, Thomas Goirand wrote: > On 06/22/2016 07:57 AM, Salvatore Bonaccorso wrote: > > Source: ironic > > Version: 1:5.1.0-1 > > Severity: grave > > Tags: security upstream > > > > Hi, > > > > the following vulnerability was published for ironic. >

Bug#827886: [PKG-Openstack-devel] Bug#827886: ironic: CVE-2016-4985: Ironic node information including credentials exposed to unathenticated users

2016-06-22 Thread Thomas Goirand
On 06/22/2016 07:57 AM, Salvatore Bonaccorso wrote: > Source: ironic > Version: 1:5.1.0-1 > Severity: grave > Tags: security upstream > > Hi, > > the following vulnerability was published for ironic. > > Setting security to grave, since looks it would allow to expose > credentials to