Bug 861482 (CVE-2014-0041) - VUL-0: CVE-2014-0041: openstack-heat-templates: use of HTTPS url and sslverify=false
Summary: VUL-0: CVE-2014-0041: openstack-heat-templates: use of HTTPS url and sslverif...
Status: RESOLVED DUPLICATE of bug 861481
Alias: CVE-2014-0041
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Minor
Target Milestone: ---
Assignee: Vincent Untz
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-01-31 10:08 UTC by Alexander Bergmann
Modified: 2014-04-22 08:38 UTC (History)
2 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2014-01-31 10:08:11 UTC
Grant Murphy found several problems within the openstack/heat-templates project.

* yum repositories being created with sslverify=false (should verify ssl certificates)

CVE-2014-0041 was assigned to this issue.

External reference:
https://bugs.launchpad.net/heat-templates/+bug/1267635
https://github.com/openstack/heat-templates/
https://bugzilla.redhat.com/show_bug.cgi?id=1059515
Comment 1 Swamp Workflow Management 2014-01-31 23:00:28 UTC
bugbot adjusting priority
Comment 2 Dirk Mueller 2014-04-22 08:38:04 UTC
It is all done in one patch

*** This bug has been marked as a duplicate of bug 861481 ***