Debian Patches

Status for zaqar/22.0.0-3

Patch Description Author Forwarded Bugs Origin Last update
finished-fixing-upstream-tests.patch Finished fixing upstream tests Patch from upstream wasn't enough.

===================================================================
Thomas Goirand <zigo@debian.org> no 2022-09-19
package-all-files.patch no
add-wsgi-application-module.patch Add wsgi application module Thomas Goirand <zigo@debian.org> no 2026-06-02
CVE-2026-66139_OSSA-2026-029_Do_not_bypass_authentication_for_requests_with_EXTRA-SPEC_header.patch CVE-2026-66139 / OSSA-2026-029: Do not bypass authentication for requests with EXTRA-SPEC header Commit 9b6edcf6ca5aca45536fb6f5038068e506c9c673 introduced
the mechanism to pass down extra headers to drivers but this introduced
queue access with all authentication and athorization check enforced.
Remove the bypass to prohibit unauthenticated access.
.
Note that the "execute" interface has never been implemented actually
in drivers so this may have no user impact really.

diff --git a/releasenotes/notes/bug-2161254-55c2748092268fb3.yaml b/releasenotes/notes/bug-2161254-55c2748092268fb3.yaml
new file mode 100644
index 0000000..a36aeae
Takashi Kajinami <kajinamit@oss.nttdata.com> yes debian upstream upstream, https://review.opendev.org/c/openstack/zaqar/+/998400 2026-07-29

All known versions for source package 'zaqar'

Links