[Openstack-security] [Bug 1550023] Re: Really bad workflow bug in top of tree

Jeremy Stanley fungi at yuggoth.org
Fri Feb 26 03:11:33 UTC 2016


Switched from public security to public and added the security bug tag
to indicate this is perhaps hardening or security feature related but
not an apparent security vulnerability.

** Information type changed from Public Security to Public

** Tags added: security

-- 
You received this bug notification because you are a member of OpenStack
Security, which is subscribed to OpenStack.
https://bugs.launchpad.net/bugs/1550023

Title:
  Really bad workflow bug in top of tree

Status in OpenStack Dashboard (Horizon):
  In Progress

Bug description:
  The associate floating ip success now takes you to a completely different web page than you started.
  This is a fundamentally flawed, broken, bad assumption.

  Ref:
  https://github.com/openstack/horizon/blob/master/openstack_dashboard/dashboards/project/access_and_security/floating_ips/workflows.py#L148

  It was probably done with the idea that you might want to change/check
  your sec group after the fact but since it's already too late now,
  don't do that....

  ALso, really breaks the stream of consciousness of working in
  instances....

  Marked as a security vulnerability as the intent here (and it fails
  badly) is to add or reinforce security. It does nothing of the sort.

To manage notifications about this bug go to:
https://bugs.launchpad.net/horizon/+bug/1550023/+subscriptions




More information about the Openstack-security mailing list