Release Notes, 2011.3.1
The 2011.3.1 release is a Diablo bugfix update for Nova and Glance.
The bugfixes contained in this release were backported from the development branches into a stable branch. The release is intended to be a relatively risk free update with no intentional regressions or API changes.
Contents
Bugs Fixed
In total, 90 launchpad bugs are fixed by this update.
Resolved Security Issues
Nova
Incorrect secret key causes user details to be revealed (CVE-2011-4076)
Path Traversal possible when downloading an image (CVE-2011-4596)
Potential directory traversal in _untarzip_image (CVE-2011-4596)
project_id could be overwritten to any value by URI value (CVE-2012-0030)
Glance
Known Issues and Limitations
Nova