← Back to team overview

yahoo-eng-team team mailing list archive

[Bug 1486565] Re: Network/Image names allows terminal escape sequence

 

Nova is an API server, it's fine to put whatever into these fields.
Should the clients scrub this, probably.

** Changed in: nova
       Status: New => Opinion

** Changed in: nova
   Importance: Undecided => Low

-- 
You received this bug notification because you are a member of Yahoo!
Engineering Team, which is subscribed to neutron.
https://bugs.launchpad.net/bugs/1486565

Title:
  Network/Image names allows terminal escape sequence

Status in Glance:
  New
Status in neutron:
  New
Status in OpenStack Compute (nova):
  Opinion
Status in OpenStack Security Advisory:
  Won't Fix

Bug description:
  This allows a malicious user to create network that will mess with
  administrator terminal when they list network.

  Steps to reproduces:

  As a user: neutron net-create $(echo -e "\E[37mhidden\x1b[f")

  As an admin: neutron net-list

To manage notifications about this bug go to:
https://bugs.launchpad.net/glance/+bug/1486565/+subscriptions