Wednesday, 2022-10-05

opendevreviewLajos Katona proposed openstack/keystone master: Opt out of authenticate.failure instead of authenticate.failed  https://review.opendev.org/c/openstack/keystone/+/82156106:44
zigoIs there a fix for CVE-2022-2447 ?07:55
frickleris there even an upstream bug for it? IMO it is also unlucky to mix terms, "token" is something different from "application credentials" in keystone10:02
tobias-urdinfeel like an easy fix tho, new tokens inherit expiration of app cred, if it break the API or current expectations i guess is a different story10:03
*** blarnath is now known as d34dh0r5311:56
*** dasm|off is now known as dasm13:43
opendevreviewJorge Merlino proposed openstack/keystonemiddleware master: Remove cache invalidation when using expired token  https://review.opendev.org/c/openstack/keystonemiddleware/+/86048117:43
d34dh0r53we’ve discussed that CVE, I don’t recall what (if anything was decided)18:14
d34dh0r53zigo, frickler, tobias-urdin ^18:17
zigod34dh0r53: So, the CVE against Keystone was wrong, it' should have been against keystonemiddleware?18:18
zigoWe're talking about CVE-2022-2447, right?18:19
zigohttps://bugs.debian.org/102127218:19
d34dh0r53right18:19
d34dh0r53yeah, that should be against keystonemiddleware18:21
d34dh0r53IIRC18:21
d34dh0r53knikolla[m]: can you confirm?18:21
zigoThanks. I'll do the work tomorrow, though the Debian security team already told me it's no-DSA (ie: no Debian Security Advisory, to be dealt with the stable release team for an update on the next point release).18:26
zigoI'll update the backports ...18:26
d34dh0r53awesome, thanks zigo18:27
zigo(ie: unofficial debian.net backports)18:30
zigod34dh0r53: I backported the patch all the way to train, without a glitch...19:29
zigoWill push and build now.19:29
zigoI was too quick to do that work: there's unit test failures...19:48
opendevreviewJorge Merlino proposed openstack/keystonemiddleware master: Remove cache invalidation when using expired token  https://review.opendev.org/c/openstack/keystonemiddleware/+/86048120:04
*** dviroel is now known as dviroel|afk21:17
*** dasm is now known as dasm|off21:34

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!