Debian Patches

Status for swift/2.30.0-4

Patch Description Author Forwarded Bugs Origin Last update
syslog_log_name.patch Set log_name for Swift services in default configs
===================================================================
Ondřej Nový <novy@ondrej.org> not-needed 2016-07-05
disable_sphinxcontrib_rsvgconverter.patch Disable sphinxcontrib.rsvgconverter extension
===================================================================
Ondřej Nový <novy@ondrej.org> not-needed 2020-02-12
set-default-workers-value.patch Set default workers value Since the package switched to uwsgi and now reads this value, it can't be
left as "auto" an commented out.
Thomas Goirand <zigo@debian.org> not-needed 2020-10-30
Add_tempurl_path_prefix_configuration_option.patch Add [filter:tempurl]/path_prefix configuration option If swiftproxy endpoint is something like /object, with URL rewriting
by haproxy, then the hmac calculation is wrong.
.
This patch adds a new path_prefix directive which is stripped away
in the URLs before calculating the tempurl hmac.

===================================================================
Kevin Allioli <kevin@linit.io> yes 2021-11-18
Fix_DB_tests_on_py311.patch [PATCH] Fix DB tests on py311 Tim Burke <tim.burke@gmail.com> no 2022-11-29
CVE-2022-47950-stable-zed.patch [PATCH] s3api: Prevent XXE injections
Previously, clients could use XML external entities (XXEs) to read
arbitrary files from proxy-servers and inject the content into the
request. Since many S3 APIs reflect request content back to the user,
this could be used to extract any secrets that the swift user could
read, such as tempauth credentials, keymaster secrets, etc.

Now, disable entity resolution -- any unknown entities will be replaced
with an empty string. Without resolving the entities, the request is
still processed.

[CVE-2022-47950]
Aymeric Ducroquetz <aymeric.ducroquetz@ovhcloud.com> no 2022-10-25

All known versions for source package 'swift'

Links