============================ #openstack-meeting: security ============================ Meeting started by gagehugo at 15:01:43 UTC. The full logs are available at http://eavesdrop.openstack.org/meetings/security/2020/security.2020-10-08-15.01.log.html . Meeting summary --------------- * LINK: https://etherpad.opendev.org/p/security-agenda agenda (gagehugo, 15:02:01) * LINK: https://launchpad.net/bugs/1895688 Authenticated RCE in blazar-dashboard (fungi, 15:05:47) * Authenticated RCE in blazar-dashboard via python expression in POST parameters (gagehugo, 15:07:20) * LINK: https://bugs.launchpad.net/blazar/+bug/1895688 (gagehugo, 15:07:27) * LINK: https://security.openstack.org/vmt-process.html#send-cve-request (gagehugo, 15:14:40) * LINK: https://security.openstack.org/vmt-process.html#send-cve-request cve request instructions (fungi, 15:15:03) * LINK: https://security.openstack.org/vmt-process.html#openstack-security-advisories-ossa template for ossa metadata (fungi, 15:16:00) * LINK: https://security.openstack.org/ossa/OSSA-2020-006.html#affects example affected version ranges list (fungi, 15:21:23) * horizon bug (gagehugo, 15:30:48) * LINK: https://bugs.launchpad.net/horizon/+bug/1898465 (gagehugo, 15:30:53) * open discussion (gagehugo, 15:36:49) * LINK: https://bugs.launchpad.net/keystonemiddleware/+bug/1892852 (gagehugo, 15:38:20) * LINK: https://bugs.launchpad.net/keystonemiddleware/+bug/1883659 (gagehugo, 15:38:50) Meeting ended at 15:45:26 UTC. People present (lines said) --------------------------- * fungi (33) * gagehugo (32) * priteau (15) * openstack (8) Generated by `MeetBot`_ 0.1.4