Jump to: navigation, search

Difference between revisions of "ReleaseNotes/2013.1.5"

(Resolved Security Issues)
(OpenStack Identity (Keystone))
Line 18: Line 18:
  
 
=== OpenStack Identity (Keystone) ===
 
=== OpenStack Identity (Keystone) ===
 +
* [http://lists.openstack.org/pipermail/openstack-announce/2013-October/000158.html OSSA 2013-028]/[https://bugs.launchpad.net/keystone/+bug/1242855 CVE-2013-4477] - Unintentional role granting with Keystone LDAP backend
 +
* [http://lists.openstack.org/pipermail/openstack-announce/2013-December/000168.html OSSA 2013-032]/[https://launchpad.net/bugs/1242597 CVE-2013-6391] - Keystone trust circumvention through EC2-style tokens
 
* [http://lists.openstack.org/pipermail/openstack-announce/2014-March/000204.html OSSA 2014-006]/[https://bugs.launchpad.net/keystone/+bug/1260080 CVE-2014-2237] - Trustee token revocation does not work with memcache backend
 
* [http://lists.openstack.org/pipermail/openstack-announce/2014-March/000204.html OSSA 2014-006]/[https://bugs.launchpad.net/keystone/+bug/1260080 CVE-2014-2237] - Trustee token revocation does not work with memcache backend
  

Revision as of 20:03, 20 March 2014

DRAFT Release Notes, 2013.1.5 DRAFT - release planned Mar 20

The 2013.1.5 release is a Grizzly bugfix update for OpenStack Compute (Nova), OpenStack Identity (Keystone), OpenStack Image Registry and Delivery Service (Glance), OpenStack Networking, OpenStack Block Storage (Cinder) and OpenStack Dashboard (Horizon). No further official Grizzly releases of these projects are planned.

The bugfixes contained in this release were backported from the development branches into a stable branch. The release is intended to be a low risk update with no intentional regressions or API changes.

Resolved Security Issues

OpenStack Compute (Nova)

OpenStack Identity (Keystone)

Bugs Fixed

In total, NN launchpad bugs are fixed by this update.

DRAFT remove milestone links before release DRAFT

DRAFT remove milestone links before release DRAFT

Known Issues and Limitations