The OpenStack Security Group publishes Security Notes to advise users of security related issues.
Published Security Notes
- 1226078 - Glance allows sharing of images between projects without consumer project approval (11 Dec 2013)
- 1237989 - Authenticated users are able to update passwords without providing their current password (22 Nov 2013)
- 1168252 - Keystone configuration should not be world readable (13 May 2013)
- 1155566 - HTTP POST limiting advised to avoid Essex/Folsom Keystone DoS (23 Apr 2013)