Back to bug 1389417
| Who | When | What | Removed | Added |
|---|---|---|---|---|
| Martin Prpič | 2016-10-27 14:31:01 UTC | CC | security-response-team | |
| Martin Prpič | 2016-10-27 14:32:53 UTC | Blocks | 1389419 | |
| Martin Prpič | 2016-10-27 15:00:57 UTC | Whiteboard | impact=moderate,public=20161101,reported=20161025,source=upstream,cvss2=4.0/AV:N/AC:H/Au:N/C:P/I:P/A:N,cvss3=7.4/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N,openstack-5/python-django=affected,openstack-6/python-django=affected,openstack-7/python-django=affected,openstack-7-optools/python-django=affected,openstack-8/python-django=affected,openstack-8-optools/python-django=affected,openstack-9/python-django=affected,openstack-9-optools/python-django=affected,openstack-10/python-django=affected,openstack-10-optools/python-django=affected,openstack-rdo/python-django=affected,ceph-1.2/Django=affected,ceph-1.3/Django=affected,rhscon-2/Django=affected,rhscon-2/python-django=affected,sam-1/Django=affected,fedora-all/python-django=affected,epel-7/python-django=affected,epel-6/Django14=affected | impact=moderate,public=20161101,reported=20161025,source=upstream,cvss2=4.0/AV:N/AC:H/Au:N/C:P/I:P/A:N,cvss3=7.4/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N,openstack-5/python-django=affected,openstack-6/python-django=affected,openstack-7/python-django=affected,openstack-7-optools/python-django=affected,openstack-8/python-django=affected,openstack-8-optools/python-django=affected,openstack-9/python-django=affected,openstack-9-optools/python-django=affected,openstack-10/python-django=affected,openstack-10-optools/python-django=affected,openstack-rdo/python-django=affected,ceph-2/Django=affected,ceph-1.3/Django=affected,rhscon-2/Django=affected,rhscon-2/python-django=affected,sam-1/Django=affected,fedora-all/python-django=affected,epel-7/python-django=affected,epel-6/Django14=affected |
| Garth Mollett | 2016-11-01 01:02:23 UTC | CC | gmollett | |
| Whiteboard | impact=moderate,public=20161101,reported=20161025,source=upstream,cvss2=4.0/AV:N/AC:H/Au:N/C:P/I:P/A:N,cvss3=7.4/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N,openstack-5/python-django=affected,openstack-6/python-django=affected,openstack-7/python-django=affected,openstack-7-optools/python-django=affected,openstack-8/python-django=affected,openstack-8-optools/python-django=affected,openstack-9/python-django=affected,openstack-9-optools/python-django=affected,openstack-10/python-django=affected,openstack-10-optools/python-django=affected,openstack-rdo/python-django=affected,ceph-2/Django=affected,ceph-1.3/Django=affected,rhscon-2/Django=affected,rhscon-2/python-django=affected,sam-1/Django=affected,fedora-all/python-django=affected,epel-7/python-django=affected,epel-6/Django14=affected | impact=low,public=20161101,reported=20161025,source=upstream,cvss2=4.0/AV:N/AC:H/Au:N/C:P/I:P/A:N,cvss3=7.4/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N,openstack-5/python-django=affected,openstack-6/python-django=affected,openstack-7/python-django=affected,openstack-7-optools/python-django=affected,openstack-8/python-django=affected,openstack-8-optools/python-django=affected,openstack-9/python-django=affected,openstack-9-optools/python-django=affected,openstack-10/python-django=affected,openstack-10-optools/python-django=affected,openstack-rdo/python-django=affected,ceph-2/Django=affected,ceph-1.3/Django=affected,rhscon-2/Django=affected,rhscon-2/python-django=affected,sam-1/Django=affected,fedora-all/python-django=affected,epel-7/python-django=affected,epel-6/Django14=affected | ||
| Garth Mollett | 2016-11-01 01:05:51 UTC | Whiteboard | impact=low,public=20161101,reported=20161025,source=upstream,cvss2=4.0/AV:N/AC:H/Au:N/C:P/I:P/A:N,cvss3=7.4/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N,openstack-5/python-django=affected,openstack-6/python-django=affected,openstack-7/python-django=affected,openstack-7-optools/python-django=affected,openstack-8/python-django=affected,openstack-8-optools/python-django=affected,openstack-9/python-django=affected,openstack-9-optools/python-django=affected,openstack-10/python-django=affected,openstack-10-optools/python-django=affected,openstack-rdo/python-django=affected,ceph-2/Django=affected,ceph-1.3/Django=affected,rhscon-2/Django=affected,rhscon-2/python-django=affected,sam-1/Django=affected,fedora-all/python-django=affected,epel-7/python-django=affected,epel-6/Django14=affected | impact=low,public=20161101,reported=20161025,source=upstream,cvss2=4.0/AV:N/AC:H/Au:N/C:P/I:P/A:N,cvss3=7.4/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N,openstack-5/python-django=wontfix,openstack-6/python-django=wontfix,openstack-7/python-django=wontfix,openstack-7-optools/python-django=wontfix,openstack-8/python-django=wontfix,openstack-8-optools/python-django=wontfix,openstack-9/python-django=wontfix,openstack-9-optools/python-django=wontfix,openstack-10/python-django=wontfix,openstack-10-optools/python-django=wontfix,openstack-rdo/python-django=affected,ceph-2/Django=affected,ceph-1.3/Django=affected,rhscon-2/Django=affected,rhscon-2/python-django=affected,sam-1/Django=affected,fedora-all/python-django=affected,epel-7/python-django=affected,epel-6/Django14=affected |
| Siddharth Sharma | 2016-11-01 02:30:53 UTC | Whiteboard | impact=low,public=20161101,reported=20161025,source=upstream,cvss2=4.0/AV:N/AC:H/Au:N/C:P/I:P/A:N,cvss3=7.4/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N,openstack-5/python-django=wontfix,openstack-6/python-django=wontfix,openstack-7/python-django=wontfix,openstack-7-optools/python-django=wontfix,openstack-8/python-django=wontfix,openstack-8-optools/python-django=wontfix,openstack-9/python-django=wontfix,openstack-9-optools/python-django=wontfix,openstack-10/python-django=wontfix,openstack-10-optools/python-django=wontfix,openstack-rdo/python-django=affected,ceph-2/Django=affected,ceph-1.3/Django=affected,rhscon-2/Django=affected,rhscon-2/python-django=affected,sam-1/Django=affected,fedora-all/python-django=affected,epel-7/python-django=affected,epel-6/Django14=affected | impact=low,public=20161101,reported=20161025,source=upstream,cvss2=4.0/AV:N/AC:H/Au:N/C:P/I:P/A:N,cvss3=7.4/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N,openstack-5/python-django=wontfix,openstack-6/python-django=wontfix,openstack-7/python-django=wontfix,openstack-7-optools/python-django=wontfix,openstack-8/python-django=wontfix,openstack-8-optools/python-django=wontfix,openstack-9/python-django=wontfix,openstack-9-optools/python-django=wontfix,openstack-10/python-django=wontfix,openstack-10-optools/python-django=wontfix,openstack-rdo/python-django=affected,ceph-2/Django=wontfix,ceph-1.3/Django=wontfix,rhscon-2/Django=wontfix,rhscon-2/python-django=affected,sam-1/Django=affected,fedora-all/python-django=affected,epel-7/python-django=affected,epel-6/Django14=affected |
| Siddharth Sharma | 2016-11-01 02:31:22 UTC | Whiteboard | impact=low,public=20161101,reported=20161025,source=upstream,cvss2=4.0/AV:N/AC:H/Au:N/C:P/I:P/A:N,cvss3=7.4/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N,openstack-5/python-django=wontfix,openstack-6/python-django=wontfix,openstack-7/python-django=wontfix,openstack-7-optools/python-django=wontfix,openstack-8/python-django=wontfix,openstack-8-optools/python-django=wontfix,openstack-9/python-django=wontfix,openstack-9-optools/python-django=wontfix,openstack-10/python-django=wontfix,openstack-10-optools/python-django=wontfix,openstack-rdo/python-django=affected,ceph-2/Django=wontfix,ceph-1.3/Django=wontfix,rhscon-2/Django=wontfix,rhscon-2/python-django=affected,sam-1/Django=affected,fedora-all/python-django=affected,epel-7/python-django=affected,epel-6/Django14=affected | impact=low,public=20161101,reported=20161025,source=upstream,cvss2=4.0/AV:N/AC:H/Au:N/C:P/I:P/A:N,cvss3=7.4/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N,openstack-5/python-django=wontfix,openstack-6/python-django=wontfix,openstack-7/python-django=wontfix,openstack-7-optools/python-django=wontfix,openstack-8/python-django=wontfix,openstack-8-optools/python-django=wontfix,openstack-9/python-django=wontfix,openstack-9-optools/python-django=wontfix,openstack-10/python-django=wontfix,openstack-10-optools/python-django=wontfix,openstack-rdo/python-django=affected,ceph-2/Django=wontfix,ceph-1.3/Django=wontfix,rhscon-2/Django=wontfix,rhscon-2/python-django=wontfix,sam-1/Django=affected,fedora-all/python-django=affected,epel-7/python-django=affected,epel-6/Django14=affected |
| Andrej Nemec | 2016-11-01 16:33:02 UTC | Summary | EMBARGOED CVE-2016-9014 python-django: DNS rebinding vulnerability when 'DEBUG=True' | CVE-2016-9014 python-django: DNS rebinding vulnerability when 'DEBUG=True' |
| Andrej Nemec | 2016-11-01 16:33:12 UTC | Group | security, qe_staff | |
| Andrej Nemec | 2016-11-01 16:35:38 UTC | Depends On | 1390684 | |
| Andrej Nemec | 2016-11-01 16:35:51 UTC | Depends On | 1390685 | |
| Andrej Nemec | 2016-11-01 16:37:15 UTC | Depends On | 1390687 | |
| Kurt Seifried | 2016-11-01 16:40:49 UTC | Whiteboard | impact=low,public=20161101,reported=20161025,source=upstream,cvss2=4.0/AV:N/AC:H/Au:N/C:P/I:P/A:N,cvss3=7.4/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N,openstack-5/python-django=wontfix,openstack-6/python-django=wontfix,openstack-7/python-django=wontfix,openstack-7-optools/python-django=wontfix,openstack-8/python-django=wontfix,openstack-8-optools/python-django=wontfix,openstack-9/python-django=wontfix,openstack-9-optools/python-django=wontfix,openstack-10/python-django=wontfix,openstack-10-optools/python-django=wontfix,openstack-rdo/python-django=affected,ceph-2/Django=wontfix,ceph-1.3/Django=wontfix,rhscon-2/Django=wontfix,rhscon-2/python-django=wontfix,sam-1/Django=affected,fedora-all/python-django=affected,epel-7/python-django=affected,epel-6/Django14=affected | impact=low,public=20161101,reported=20161025,source=upstream,cvss2=4.0/AV:N/AC:H/Au:N/C:P/I:P/A:N,cvss3=7.4/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N,openstack-5/python-django=wontfix,openstack-6/python-django=wontfix,openstack-7/python-django=wontfix,openstack-7-optools/python-django=wontfix,openstack-8/python-django=wontfix,openstack-8-optools/python-django=wontfix,openstack-9/python-django=wontfix,openstack-9-optools/python-django=wontfix,openstack-10/python-django=wontfix,openstack-10-optools/python-django=wontfix,openstack-rdo/python-django=affected,ceph-2/Django=wontfix,ceph-1.3/Django=wontfix,rhscon-2/Django=wontfix,rhscon-2/python-django=wontfix,sam-1/Django=wontfix,fedora-all/python-django=affected,epel-7/python-django=affected,epel-6/Django14=affected |
| Adam Mariš | 2016-11-02 07:45:30 UTC | Priority | medium | low |
| CC | amaris | |||
| Severity | medium | low | ||
| Adam Mariš | 2016-11-08 16:11:08 UTC | CC | amaris | |
| PnT Account Manager | 2018-01-31 00:06:20 UTC | CC | aortega | |
| PnT Account Manager | 2018-06-29 22:15:34 UTC | CC | kseifried | |
| Product Security DevOps Team | 2019-06-08 03:01:24 UTC | Status | NEW | CLOSED |
| Resolution | --- | WONTFIX | ||
| Last Closed | 2019-06-08 03:01:24 UTC | |||
| Product Security DevOps Team | 2019-09-29 13:58:49 UTC | Whiteboard | impact=low,public=20161101,reported=20161025,source=upstream,cvss2=4.0/AV:N/AC:H/Au:N/C:P/I:P/A:N,cvss3=7.4/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N,openstack-5/python-django=wontfix,openstack-6/python-django=wontfix,openstack-7/python-django=wontfix,openstack-7-optools/python-django=wontfix,openstack-8/python-django=wontfix,openstack-8-optools/python-django=wontfix,openstack-9/python-django=wontfix,openstack-9-optools/python-django=wontfix,openstack-10/python-django=wontfix,openstack-10-optools/python-django=wontfix,openstack-rdo/python-django=affected,ceph-2/Django=wontfix,ceph-1.3/Django=wontfix,rhscon-2/Django=wontfix,rhscon-2/python-django=wontfix,sam-1/Django=wontfix,fedora-all/python-django=affected,epel-7/python-django=affected,epel-6/Django14=affected | |
| Hardik Vyas | 2020-10-09 07:05:19 UTC | CC | hvyas |
Back to bug 1389417