From e4b61aa71e22dacb86aa18116eb8ab32f24f4984 Mon Sep 17 00:00:00 2001 From: Neha Ojha Date: Wed, 16 Dec 2020 17:15:25 +0000 Subject: [PATCH] doc/releases/nautilus.rst: add release notes for 14.2.16 Signed-off-by: Neha Ojha --- doc/releases/nautilus.rst | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) diff --git a/doc/releases/nautilus.rst b/doc/releases/nautilus.rst index be096999089..e52285753fa 100644 --- a/doc/releases/nautilus.rst +++ b/doc/releases/nautilus.rst @@ -1,3 +1,24 @@ +v14.2.16 Nautilus +================= + +This is the 16th backport release in the Nautilus series. This release fixes a +security flaw in CephFS. We recommend users to update to this release. + +Notable Changes +--------------- + +* CVE-2020-27781 : OpenStack Manila use of ceph_volume_client.py library allowed + tenant access to any Ceph credential's secret. (Kotresh Hiremath Ravishankar, + Ramana Raja) + + +Changelog +--------- + +* pybind/ceph_volume_client: disallow authorize on existing auth ids (Kotresh + Hiremath Ravishankar, Ramana Raja) + + v14.2.15 Nautilus =================