Debian Patches
Status for zaqar/22.0.0-3
| Patch | Description | Author | Forwarded | Bugs | Origin | Last update |
|---|---|---|---|---|---|---|
| finished-fixing-upstream-tests.patch | Finished fixing upstream tests Patch from upstream wasn't enough. =================================================================== |
Thomas Goirand <zigo@debian.org> | no | 2022-09-19 | ||
| package-all-files.patch | no | |||||
| add-wsgi-application-module.patch | Add wsgi application module | Thomas Goirand <zigo@debian.org> | no | 2026-06-02 | ||
| CVE-2026-66139_OSSA-2026-029_Do_not_bypass_authentication_for_requests_with_EXTRA-SPEC_header.patch | CVE-2026-66139 / OSSA-2026-029: Do not bypass authentication for requests with EXTRA-SPEC header Commit 9b6edcf6ca5aca45536fb6f5038068e506c9c673 introduced the mechanism to pass down extra headers to drivers but this introduced queue access with all authentication and athorization check enforced. Remove the bypass to prohibit unauthenticated access. . Note that the "execute" interface has never been implemented actually in drivers so this may have no user impact really. diff --git a/releasenotes/notes/bug-2161254-55c2748092268fb3.yaml b/releasenotes/notes/bug-2161254-55c2748092268fb3.yaml new file mode 100644 index 0000000..a36aeae |
Takashi Kajinami <kajinamit@oss.nttdata.com> | yes | debian upstream | upstream, https://review.opendev.org/c/openstack/zaqar/+/998400 | 2026-07-29 |
