#openstack-security: security

Meeting started by fungi at 15:01:11 UTC (full logs).

Meeting summary

    1. https://etherpad.opendev.org/p/security-agenda Meeting Agenda (fungi, 15:03:13)

  1. Prior Actions (fungi, 15:04:13)
    1. https://meetings.opendev.org/meetings/security/2022/security.2022-09-01-15.02.html (previous minutes) (fungi, 15:05:01)
    2. ACTION: fungi propose xstatic discussion topic on horizon ptg agenda (fungi, 15:09:06)
    3. ACTION: fungi update ossn/security-doc members in gerrit and launchpad (fungi, 15:10:45)
    4. https://review.opendev.org/850003 Gracefully ERROR in _init_instance if vnic_type changed (fungi, 15:11:50)
    5. https://launchpad.net/bugs/1981813 Compute service fails to restart if the vnic_type of a bound port changed from direct to macvtap (CVE-2022-37394) (fungi, 15:18:59)

  2. Public Bug Reports (fungi, 15:22:31)
    1. https://storyboard.openstack.org/#!/story/2010004 Remote code execution: Trove backup (fungi, 15:23:29)
    2. https://launchpad.net/bugs/1989008 Lax rulesets leading to privilege escalation vulnerabilities (fungi, 15:24:07)
    3. https://bugzilla.redhat.com/show_bug.cgi?id=2105419 Application credential token remains valid longer than expected (fungi, 15:25:01)

  3. PTG Planning (fungi, 15:27:22)
    1. https://etherpad.opendev.org/p/oct2022-ptg-openstack-security (fungi, 15:28:45)

  4. Open Discussion (fungi, 15:32:46)
    1. https://wiki.openstack.org/wiki/Security-SIG (fungi, 15:33:25)
    2. https://lists.openstack.org/pipermail/openstack-discuss/2022-October/030755.html Openstack Security Assessments (fungi, 15:35:06)


Meeting ended at 15:45:34 UTC (full logs).

Action items

  1. fungi propose xstatic discussion topic on horizon ptg agenda
  2. fungi update ossn/security-doc members in gerrit and launchpad


Action items, by person

  1. fungi
    1. fungi propose xstatic discussion topic on horizon ptg agenda
    2. fungi update ossn/security-doc members in gerrit and launchpad


People present (lines said)

  1. fungi (61)
  2. opendevmeet (3)
  3. gagehugo (3)


Generated by MeetBot 0.1.4.