15:01:54 <gagehugo> #startmeeting security
15:03:10 <gagehugo> #link https://etherpad.opendev.org/p/security-agenda agenda
15:04:33 <fungi> we made a trove bug public
15:04:50 <fungi> other than that i don't think i have much to cover
15:07:24 <gagehugo> I was asked about including a slide for openstack 10 years about the security sig, so I just included a section from the security sig wiki page
15:09:18 <fungi> how would folks feel about moving the wiki page into governance-sigs repo? like i did for https://governance.openstack.org/sigs/tact-sig.html
15:09:27 <fungi> #link https://governance.openstack.org/sigs/tact-sig.html sample sig page
15:13:15 <fungi> on the trove report, that was bug 1884457
15:13:15 <openstack> bug 1884457 in OpenStack DBaaS (Trove) "Remote Code Execution in trove-conductor" [Undecided,New] https://launchpad.net/bugs/1884457
15:13:26 <fungi> #link https://launchpad.net/bugs/1884457 Remote Code Execution in trove-conductor
15:14:06 <fungi> this turned out to be a known risk, trove currently recommends using a service tenant for all the trove instance resources in any deployments where trove users are not trusted
15:15:34 <fungi> otherwise you could do things like attach the trove storage device to a general purpose server instance under the control of the user and inject arbitrary code or grab message bus credentials
