15:00:26 #startmeeting security 15:00:31 Meeting started Thu Jan 21 15:00:26 2021 UTC and is due to finish in 60 minutes. The chair is gagehugo. Information about MeetBot at http://wiki.debian.org/MeetBot. 15:00:32 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 15:00:35 The meeting name has been set to 'security' 15:00:40 #link https://etherpad.opendev.org/p/security-agenda agenda 15:01:26 ahoy 15:01:56 o/ 15:05:50 \o 15:06:02 Nothing on the agenda today 15:06:07 #topic open discussion 15:06:12 Anyone have anything? 15:08:18 #link https://bugs.launchpad.net/ossa Public reports of suspected vulnerabilities in need of review 15:08:58 i think there are 29 at the moment (if you're logged in as a vulnerability manager you may see a higher number) 15:10:00 revisiting private reports, it seems we have one where the embargo has expired too, i'll open it up now 15:11:50 #link https://launchpad.net/bugs/1892848 XSS in adding JavaScript into the ‘Subnet Name’ field 15:11:51 Launchpad bug 1892848 in OpenStack Security Advisory "XSS in adding JavaScript into the ‘Subnet Name’ field" [Undecided,Incomplete] 15:12:48 so that brings the total up to 30 which would be nice to get some folks to weigh in on 15:13:10 i should revisit my earlier idea to sort them by project and send a list to th eopenstack-discuss ml 15:13:44 I'll try to make some time to review some of those. Not sure how useful I'll be though. 😅 15:18:54 thanks fungi, anyone else have anything? 15:19:46 that was all i had for this week. i'll try to send something to the ml, but infra fires have dominated my available time recently 15:22:23 yeah, coming back from vacation has consumed most of my time lately 15:22:38 thanks fungi, redrobot! Have a good rest of the week! 15:22:43 #endmeeting