diff --git a/README.rst b/README.rst index 4cbd0b1b1d1..458f424d31c 100644 --- a/README.rst +++ b/README.rst @@ -7,6 +7,22 @@ OpenStack Cinder .. Change things from this point on +.. warning:: + The stable/ussuri branch of cinder does not contain a fix for + CVE-2023-2088_. Be aware that such a fix must span cinder, os-brick, + nova, and, depending on your deployment configuration, glance_store + and ironic. *The Cinder project team advises against using the code + in this branch unless a mitigation against CVE-2023-2088 is applied.* + + .. _CVE-2023-2088: https://nvd.nist.gov/vuln/detail/CVE-2023-2088 + + References: + + * https://nvd.nist.gov/vuln/detail/CVE-2023-2088 + * https://bugs.launchpad.net/cinder/+bug/2004555 + * https://security.openstack.org/ossa/OSSA-2023-003.html + * https://wiki.openstack.org/wiki/OSSN/OSSN-0092 + OpenStack Cinder is a storage service for an open cloud computing service. You can learn more about Cinder at: