Monday, 2026-05-04

opendevreviewGoutham Pacha Ravi proposed openstack/ossa master: Add OSSA-2026-009 (CVE-2026-43002)  https://review.opendev.org/c/openstack/ossa/+/98648006:27
gouthamra CVE assignment came through for https://review.opendev.org/c/openstack/ossa/+/986480 and the Horizon team has managed to backport the bug fix to the affected release (2026.1). Could use a pair of eyes when you're around JayF rosmaita06:29
opendevreviewGoutham Pacha Ravi proposed openstack/ossa master: Add OSSA-2026-009 (CVE-2026-43002)  https://review.opendev.org/c/openstack/ossa/+/98648006:29
oschwartHello folks, good day. I am the current Designate PTL and I have just seen Goutham's email from last Friday09:27
oschwartI wasn't added to the https://launchpad.net/~designate-coresec team, can anyone add me?09:28
opendevreviewcid proposed openstack/ossa master: Add OSSA-2026-010: Credential Forwarding to URLs  https://review.opendev.org/c/openstack/ossa/+/98686319:55
JayFgouthamr: rosmaita: https://review.opendev.org/c/openstack/ossa/+/986863 is ready for announcement tomorrow, if it LGTY20:15
rosmaitawill take a look20:16
JayFactually, have a suggested revision20:17
JayFplease wait for my comment, I just found a missing thing,.20:17
JayFnevermind, I'm wrong I believe20:18
rosmaitaack20:18
gouthamrhey JayF! can take a look too20:21
gouthamrJayF: how did the CVE get assigned? did someone else issue it?20:21
JayFCID emailed a request for it based on my instruction. Just delegated it to him since it was a non-embargoed bug and I had shown him the process I followed for the previous unembargoed CVE bug.20:22
gouthamrJayF: since the bug's public, i expected that MITRE would already release the CVE details.. but, https://www.cve.org/CVERecord?id=CVE-2026-42997 thinks it was issued by a CNA?20:22
JayFIt may have not been listed as a public one when filed with MITRE, those show up weird until approved.20:22
JayFspeaking of, I need to email them about one I did recently, I think -008, actually, and link to the OSSA20:23
JayFI suspect when I did -008 I didn't click a checkbox properly for an embargoed change, and this got copied into his -009 ticket20:24
gouthamrack, i am still grok-ing some things about the CVE requests 20:25
gouthamri requested one for Keystone several times and never got a notification; seemed super weird. for all i can tell, there's some automation breaking with an error that's not surfaced to the requester, and MITRE doesn't tell you either20:26
gouthamrfor this one: https://bugs.launchpad.net/keystone/+bug/214171320:27
JayFyep, they are highly inconsistent20:28
JayFincluding things like making the CVE appear right in their web UI20:28
JayFif it was assigned this morning (I think it was), I'm not shocked it's not displaying as you'd expect on cve.org20:28
gouthamryes20:29
gouthamrawesome, let's coordinate 009 and 010 then, timing wise20:29
opendevreviewGoutham Pacha Ravi proposed openstack/ossa master: Add OSSA-2026-009 (CVE-2026-43002)  https://review.opendev.org/c/openstack/ossa/+/98648020:32
opendevreviewGoutham Pacha Ravi proposed openstack/ossa master: Add OSSA-2026-009 (CVE-2026-43002)  https://review.opendev.org/c/openstack/ossa/+/98648020:33
rosmaitagouthamr: LGTM, is there any reason not to go ahead and merge it now?20:43
gouthamrno reason rosmaita 20:44
rosmaita:D20:44
opendevreviewMerged openstack/ossa master: Add OSSA-2026-009 (CVE-2026-43002)  https://review.opendev.org/c/openstack/ossa/+/98648020:47
gouthamrty rosmaita JayF 21:11
gouthamrJayF: when was the "molds" feature deprecated?21:11
JayFlong enough ago we should've removed it21:12
JayFissue is with that OSSA: if the driver it's in is enabled, you're vuln whether you use the feature or not21:12
gouthamrah, i think, because of the way the current statement is written, i'd ask to include that detail21:13
JayFremoving that feature from master is in the gate, but our gate is busted, but we won't release Hibiscus with it21:13
gouthamrack, fair21:13

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!