Monday, 2022-10-31

*** mhen_ is now known as mhen02:31
*** prometheanfire is now known as Guest006:40
*** osmanlicilegi is now known as Guest306:40
opendevreviewMilana Levy proposed openstack/barbican-tempest-plugin master: DNM:Added a test for automate an exploit that was introduced in "cve_2022_3100" The exploit is that a malicious user with a Keystone account is able to decrypt any secret as long as they know the secret's ID by using a specifically crafted query string: GET /v1/secrets/{secret-id}/payload?target.secret.read=read  https://review.opendev.org/c/openstack/barbican-tempe07:30
opendevreviewMilana Levy proposed openstack/barbican-tempest-plugin master: Added a test for automate an exploit that was introduced in "cve_2022_3100" The exploit is that a malicious user with a Keystone account is able to decrypt any secret as long as they know the secret's ID by using a specifically crafted query string: GET /v1/secrets/{secret-id}/payload?target.secret.read=read  https://review.opendev.org/c/openstack/barbican-tempest-p07:32
opendevreviewMilana Levy proposed openstack/barbican-tempest-plugin master: Intreduce a new test for "cve_2022_3100"  https://review.opendev.org/c/openstack/barbican-tempest-plugin/+/86279610:12
*** jamesdenton_ is now known as jamesdenton12:24
*** Guest0 is now known as prometheanfire14:18

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!