[swift][security-sig] Please revisit your open vulnerability report
10 May
2021
10 May
'21
6:06 p.m.
Please help the OpenStack Vulnerability Management Team by taking a look at the following report: Swift tempurl middleware reveals signatures in the logfiles (CVE-2017-8761) https://launchpad.net/bugs/1685798 Can it be exploited by a nefarious actor, and if so, how? Is it likely to be fixable in all our supported stable branches, respecting stable backport policy? What deployment configurations and options might determine whether a particular installation is susceptible? This is the sort of feedback we depend on to make determinations regarding whether and how to keep the public notified, so they can make informed decisions. Thanks for doing your part to keep our users safe! -- Jeremy Stanley
1280
Age (days ago)
1280
Last active (days ago)
0 comments
1 participants
participants (1)
-
Jeremy Stanley