yahoo-eng-team team mailing list archive
-
yahoo-eng-team team
-
Mailing list archive
-
Message #46158
[Bug 1486565] Re: Network/Image names allows terminal escape sequence
Nova is an API server, it's fine to put whatever into these fields.
Should the clients scrub this, probably.
** Changed in: nova
Status: New => Opinion
** Changed in: nova
Importance: Undecided => Low
--
You received this bug notification because you are a member of Yahoo!
Engineering Team, which is subscribed to neutron.
https://bugs.launchpad.net/bugs/1486565
Title:
Network/Image names allows terminal escape sequence
Status in Glance:
New
Status in neutron:
New
Status in OpenStack Compute (nova):
Opinion
Status in OpenStack Security Advisory:
Won't Fix
Bug description:
This allows a malicious user to create network that will mess with
administrator terminal when they list network.
Steps to reproduces:
As a user: neutron net-create $(echo -e "\E[37mhidden\x1b[f")
As an admin: neutron net-list
To manage notifications about this bug go to:
https://bugs.launchpad.net/glance/+bug/1486565/+subscriptions