gagehugo | #startmeeting security | 15:01 |
---|---|---|
opendevmeet | Meeting started Thu Aug 5 15:01:54 2021 UTC and is due to finish in 60 minutes. The chair is gagehugo. Information about MeetBot at http://wiki.debian.org/MeetBot. | 15:01 |
opendevmeet | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 15:01 |
opendevmeet | The meeting name has been set to 'security' | 15:01 |
fungi | ahoy! | 15:03 |
gagehugo | o/ | 15:03 |
gagehugo | #link https://etherpad.opendev.org/p/security-agenda agenda | 15:04 |
gagehugo | Nothing really on the agenda | 15:04 |
gagehugo | #topic open discussion | 15:04 |
gagehugo | I need to update the irc meeting references still | 15:04 |
fungi | yeah, i'm hoping to start on that keystone ossa today | 15:05 |
fungi | the pci-dss account oracle one | 15:05 |
gagehugo | yup | 15:05 |
gagehugo | ping me when you get it up and I'll review it | 15:06 |
fungi | do you generally agree with the direction i was going with my last comment on that one? | 15:06 |
gagehugo | I think so, lemme double check | 15:06 |
fungi | (not including account lockout as an actual bug) | 15:06 |
gagehugo | ok yeah | 15:07 |
gagehugo | the lockout part is not the bug focus | 15:07 |
gagehugo | more on the oracle | 15:07 |
fungi | okay, cool. i'll focus on the other two points with the impact description | 15:08 |
fungi | #link https://launchpad.net/bugs/1688137 PCI-DSS account lock out DoS and account UUID lookup oracle | 15:09 |
fungi | so i'll retitle the bug and leave the "account lock out DoS" part out of the impact description | 15:10 |
gagehugo | sounds good | 15:11 |
gagehugo | oh | 15:13 |
gagehugo | I'll reserve a timeslot for the PTG as well | 15:13 |
gagehugo | hopefully it's not too late | 15:16 |
fungi | i'm sure they'll be able to squeeze us in, thanks | 15:17 |
fungi | and sorry i'm so quiet, trying to do three meetings at once again | 15:18 |
gagehugo | I am double booked right now too, no worries haha | 15:18 |
fungi | i'll try to get another set of reminders out to the ml about unresolved public vulnerability reports next week, time permitting | 15:19 |
fungi | though our list is pretty small now, and there's a couple more about the incomplete rbac situation i plan on marking won't fix for advisory tasks | 15:19 |
gagehugo | hmm ok | 15:20 |
gagehugo | I need to hop on another call, thanks as always fungi | 15:20 |
gagehugo | #endmeeting | 15:20 |
opendevmeet | Meeting ended Thu Aug 5 15:20:51 2021 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 15:20 |
opendevmeet | Minutes: https://meetings.opendev.org/meetings/security/2021/security.2021-08-05-15.01.html | 15:20 |
opendevmeet | Minutes (text): https://meetings.opendev.org/meetings/security/2021/security.2021-08-05-15.01.txt | 15:20 |
opendevmeet | Log: https://meetings.opendev.org/meetings/security/2021/security.2021-08-05-15.01.log.html | 15:20 |
fungi | thanks gagehugo! | 15:21 |
fungi | i probably should have mentioned during the meeting that we published our first two advisories of the year last month: | 15:26 |
fungi | https://security.openstack.org/ossa/OSSA-2021-001.html Anti-spoofing bypass for Open vSwitch networks | 15:27 |
fungi | https://security.openstack.org/ossa/OSSA-2021-002.html Open Redirect in noVNC proxy | 15:27 |
opendevreview | Jeremy Stanley proposed openstack/ossa master: Add OSSA-2021-002 (TBD) https://review.opendev.org/c/openstack/ossa/+/803640 | 18:28 |
fungi | gagehugo: ^ one thing i'm unclear on is whether there are ways to have a login attempt raise AccountLocked without setting lockout_failure_attempts in the config | 18:29 |
fungi | i assumed there are other ways an account might be locked (for example, manually by an admin?), but if lockout_failure_attempts is really the only way to do that then we can change the last sentence of the description to indicate that's a mitigating factor | 18:30 |
fungi | assuming the description looks sane, i'll request a cve from mitre for that | 18:30 |
fungi | unrelated, i've closed our advisory bugtasks as "won't fix" on the following public reports: | 18:37 |
fungi | https://launchpad.net/bugs/1784259 Neutron RBAC not working for multiple extensions | 18:37 |
fungi | https://launchpad.net/bugs/1933269 Project admin gets treated as Global Admin with Secure RBAC | 18:38 |
gagehugo | Ill look once I get home | 18:46 |
fungi | thanks! the sooner i know one way or the other, the sooner i can get the cve request going for that one | 18:47 |
fungi | but no rush, i can always rejigger the publication date. this bug was opened more than four years ago, a few more days won't make a difference | 18:48 |
gagehugo | I don't think AccountLocked can be raised if that setting is not set | 19:16 |
gagehugo | I know it doesn't get raised with an LDAP backend | 19:16 |
gagehugo | just local users | 19:16 |
gagehugo | I am also pretty sure an admin can't "lock" a user, they can disable a user though but that is different | 19:17 |
fungi | gagehugo: aha, thanks, that makes it a slightly different matter. i'll reword accordingly. thanks!!! | 19:51 |
gagehugo | I am pretty sure the check to throw that exception is only done if that flag is set | 19:52 |
fungi | great, so fairly narrow risk in that case | 19:53 |
opendevreview | Jeremy Stanley proposed openstack/ossa master: Add OSSA-2021-003 (TBD) https://review.opendev.org/c/openstack/ossa/+/803640 | 19:58 |
fungi | gagehugo: ^ there it is with the revised title and description | 19:58 |
-opendevstatus- NOTICE: The Gerrit service on review.opendev.org is going down for a quick restart to adjust its database connection configuration, and should return to service momentarily | 20:04 | |
gagehugo | fungi: 08/10? | 20:07 |
fungi | that's tuesday, yeah? | 20:10 |
fungi | i still need to get a cve assigned | 20:10 |
fungi | suspecting it may take through the weekend | 20:10 |
fungi | that's why the change is in wip state still | 20:11 |
fungi | though if that new wording is good with you, i'll use it to request a cve shortly | 20:11 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!