Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Wip mimic rgw fixes #34504

Merged
merged 3 commits into from Apr 9, 2020
Merged

Wip mimic rgw fixes #34504

merged 3 commits into from Apr 9, 2020

Conversation

theanalyst
Copy link
Member

@theanalyst theanalyst commented Apr 9, 2020

mattbenjamin and others added 3 commits April 8, 2020 17:34
Signed-off-by: Matt Benjamin <mbenjamin@redhat.com>
Reviewed-by: Casey Bodley <cbodley@redhat.com>
(cherry picked from commit d8dd5e513c0c62bbd7d3044d7e2eddcd897bd400)
As per Robin's comments and S3 spec

Signed-off-by: Abhishek Lekshmanan <abhishek@suse.com>
S3 GetObject permits overriding response header values, but those inputs
need to be validated to insure only characters that are valid in an HTTP
header value are present.

Credit: Initial vulnerability discovery by William Bowling (@wcbowling)
Credit: Further vulnerability discovery by Robin H. Johnson <rjohnson@digitalocean.com>
Signed-off-by: Robin H. Johnson <rjohnson@digitalocean.com>
@theanalyst theanalyst merged commit ecd14d3 into mimic Apr 9, 2020
@theanalyst theanalyst deleted the wip-mimic-rgw-fixes branch April 9, 2020 18:29
@yuriw
Copy link
Contributor

yuriw commented Apr 9, 2020

@smithfarm smithfarm added this to the mimic milestone Apr 16, 2020
@smithfarm smithfarm added the rgw label Apr 16, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
4 participants