Tuesday, 2022-11-29

*** atmark is now known as Guest30502:10
rajivHi, is there a fix for CVE-2022-4134 ? online articles suggest its in-progress13:16
croelandtrajiv: this is https://wiki.openstack.org/wiki/OSSN/OSSN-0090 , right? I think the fix is the dual glance-api setup13:38
rajivyes, this is the mitigation : https://access.redhat.com/security/cve/CVE-2022-4134 ?13:41
rajivif show_multiple_locations is not enabled in my setup i am exposed to this CVE correct ?13:42
croelandtif it's not enabled, I think you are not affected13:45
rajivokay, docu says this flag is deprecated and removal from Newton release13:46
croelandtyeah but it's unfortunately still there 13:46
rajivhttps://docs.openstack.org/glance/yoga/configuration/glance_api.html#DEFAULT.show_multiple_locations13:46
rajivokay, thanks13:46
croelandtshould be removed once we have https://review.opendev.org/c/openstack/glance-specs/+/84088213:46

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!