1677723
|
#1677723 |
[OSSA-2017-004] federated user gets wrong role (CVE-2017-2673)
|
|
2
Critical
|
Boris Bobrov
|
10
Fix Released
|
1658116
|
#1658116 |
Wrong migration step run when file names are the same
|
|
3
High
|
Ron De Rose
|
10
Fix Released
|
1662762
|
#1662762 |
Authentication for LDAP user fails at MFA rule check
|
|
3
High
|
Matthew Edmonds
|
10
Fix Released
|
1675377
|
#1675377 |
Lack rights for regular user: unability to create ec2 credentials
|
|
3
High
|
David Stanek
|
10
Fix Released
|
1675822
|
#1675822 |
Allow policy actions in code to be importable for RBAC testing
|
|
3
High
|
|
10
Fix Released
|
1657452
|
#1657452 |
Incompatibility with python-webob 1.7.0
|
|
4
Medium
|
David Stanek
|
10
Fix Released
|
1659053
|
#1659053 |
use uuids with pycadf
|
|
4
Medium
|
Gage Hugo
|
10
Fix Released
|
1662514
|
#1662514 |
Removing group role assignments results in overly broad revocation events
|
|
4
Medium
|
prashkre
|
10
Fix Released
|
1663627
|
#1663627 |
Running db_sync --check against new installs fails
|
|
4
Medium
|
Richard
|
10
Fix Released
|
1670380
|
#1670380 |
GET /v3/auth/catalog/ docs are out of sync
|
|
4
Medium
|
Anthony Washington
|
10
Fix Released
|
1670382
|
#1670382 |
[ldap]/group_members_are_ids isn't a whitelisted option
|
|
4
Medium
|
Richard
|
10
Fix Released
|
1674415
|
#1674415 |
keystone exception messages are not translating when locale is passed
|
|
4
Medium
|
prashkre
|
10
Fix Released
|
1684820
|
#1684820 |
GET /role_assignments?include_names API is blocked with 404 error when a user doesn't exists in identity backend
|
|
4
Medium
|
Kristi Nikolla
|
10
Fix Released
|
1693510
|
#1693510 |
GET /v3/role_assignments?effective&include_names API is blocked with 404 error when a group doesn't exists in identity backend
|
|
4
Medium
|
Matthew Edmonds
|
10
Fix Released
|
1501032
|
#1501032 |
incorrect method list is returned when scoping tokens with federation
|
|
5
Low
|
Ron De Rose
|
10
Fix Released
|
1579014
|
#1579014 |
"name" field is not validated properly for endpoint creation
|
|
5
Low
|
Samuel Pilla
|
10
Fix Released
|
1665706
|
#1665706 |
devref api curl examples are hard to read - not formatted
|
|
5
Low
|
Travis Tripp
|
10
Fix Released
|
1667194
|
#1667194 |
[api] The param "X-Subject-Token" is not needed in API "GET /v3/auth/projects"
|
|
5
Low
|
Kristi Nikolla
|
10
Fix Released
|
1676497
|
#1676497 |
bindep returns wrong package name for libssl-dev in redhat
|
|
5
Low
|
Kristi Nikolla
|
10
Fix Released
|
1676925
|
#1676925 |
db_sync --expand may run downtime-incurring operations in upgrades to Newton
|
|
5
Low
|
Dolph Mathews
|
10
Fix Released
|
1687115
|
#1687115 |
LDAPServerConnectionError gives out too much info
|
|
5
Low
|
Matthew Edmonds
|
10
Fix Released
|
1077282
|
#1077282 |
Remove KVS Backend
|
|
6
Wishlist
|
Morgan Fainberg
|
10
Fix Released
|
1523369
|
#1523369 |
clean a user's default project if the project has been deleted
|
|
6
Wishlist
|
Anthony Washington
|
10
Fix Released
|
1590805
|
#1590805 |
Revoking "admin" role from a group invalidates domain admin's token
|
|
6
Wishlist
|
|
10
Fix Released
|
1667367
|
#1667367 |
V2 role create does not allow spaces in the role description
|
|
1
Undecided
|
Tin Lam
|
10
Fix Released
|
1668563
|
#1668563 |
Unclear error when attempting to create duplicate resources with certain names
|
|
1
Undecided
|
Colleen Murphy
|
10
Fix Released
|