15:00:12 #startmeeting security 15:00:13 Meeting started Thu Jul 30 15:00:12 2020 UTC and is due to finish in 60 minutes. The chair is gagehugo. Information about MeetBot at http://wiki.debian.org/MeetBot. 15:00:14 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 15:00:16 The meeting name has been set to 'security' 15:00:21 #link https://etherpad.opendev.org/p/security-agenda agenda 15:00:28 o/ 15:01:18 ahoy 15:04:22 fungi: o/ 15:04:50 oh good, i was worried for a moment that o/ was actually the international emoticon for "i'm drowning, help" 15:05:53 o/ 15:06:14 It could be 15:06:42 fungi: do you have anything this week? 15:06:53 unfortunately July was a busy month for me 15:07:47 uh, yeah, let's see... 15:08:24 #link https://launchpad.net/bugs/1888722 The Nova api permits any possible hostname, including for example "../.." or "; --" or "hostname.openstack.org" 15:08:26 Launchpad bug 1888722 in OpenStack Compute (nova) "The Nova api permits any possible hostname, including for example "../.." or "; --" or "hostname.openstack.org"" [Undecided,New] 15:08:51 #link https://launchpad.net/bugs/1889055 security issue - some command injection vulnerability found and fixed 15:08:53 Launchpad bug 1889055 in OpenStack Security Advisory "security issue - some command injection vulnerability found and fixed" [Undecided,Invalid] 15:09:06 those were made public in the past week 15:10:01 cool 15:10:05 unrelated, the open infrastructure summit event organizers at the osf are looking for additional programming committee members to oversee talk selection for the security track 15:10:20 they need at least one more, but several would be great 15:10:41 if anyone sees this and is interested in helping with that, feel free to reach out to me and i can put you in touch 15:11:44 Do you know the dates for the selection process? 15:11:52 commitment is fairly minimal. a few hours a week for maybe a couple weeks to review talk proposal abstracts, rank them and provide feedback 15:12:08 I could potentially help if I can plan ahead 15:12:19 looking for schedule details now 15:13:44 #link https://cfp.openstack.org/ speakers will be informed by mid August 2020 15:13:59 10 hours, August 18 - 28 - CFP review and final selection 15:14:09 thanks! 15:14:59 fungi: you can put me down, I will make plans to be available 15:15:20 gagehugo: great, i'll let them know to get in touch 15:16:16 Luzi_: i think they've also been trying to reach out to you since you did it recently, though i totally understand if that's not something you're up for (i did it a few years myself and got burned out on it) 15:17:53 fungi, they did ask me, and i am willing to help :) 15:18:19 oh, cool i'll make sure they know, it's possible they missed your reply 15:18:27 they got it 15:18:29 and thanks so much!!! 15:18:31 :) 15:21:55 yeah, now i see they contacted you after the last time i checked in with them, cool 15:23:38 i don't think i had anything else for this week 15:24:17 though i guess that's also a good opportunity to remind everyone the cfp is open, and obviously there's a security track, so feel free to propose stuff you want to give a talk on 15:24:57 yup 15:26:07 and it's a virtual event, so you can give a talk from the comfort of your own porch/living room/dank basement/wherever 15:27:47 from my patio as a tornado goes by in the background 15:28:11 and i'll watch it from inside the eye of a hurricane 15:29:35 ++ 15:30:23 I need to run, thanks Luzi_ fungi 15:30:28 #endmeeting