============================ #openstack-meeting: security ============================ Meeting started by gagehugo at 15:00:12 UTC. The full logs are available at http://eavesdrop.openstack.org/meetings/security/2020/security.2020-07-30-15.00.log.html . Meeting summary --------------- * LINK: https://etherpad.opendev.org/p/security-agenda agenda (gagehugo, 15:00:21) * LINK: https://launchpad.net/bugs/1888722 The Nova api permits any possible hostname, including for example "../.." or "; --" or "hostname.openstack.org" (fungi, 15:08:24) * LINK: https://launchpad.net/bugs/1889055 security issue - some command injection vulnerability found and fixed (fungi, 15:08:51) * LINK: https://cfp.openstack.org/ speakers will be informed by mid August 2020 (fungi, 15:13:44) Meeting ended at 15:30:28 UTC. People present (lines said) --------------------------- * fungi (22) * gagehugo (16) * openstack (5) * Luzi_ (5) Generated by `MeetBot`_ 0.1.4