On 09/30/2012 08:04 PM, Yves-Alexis Perez wrote:
Package: keystone
Severity: grave
Tags: security
Justification: user security hole
Hi,
two more CVEs were allocated for keystone:
CVE-2012-4456: fails to validate tokens in Admin API
CVE-2012-4457: fails to raise Unauthorized user error for disabled
tenant
Could you upload isolated fixes to unstable?
Regards,
Hi,
I normally receive patches when such problem happen in Openstack, though
this time I didn't. Do you have URLs for the patches?
Thomas
--
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org