• Bug#1104964: marked as pending in ironic

    From Thomas Goirand@21:1/5 to All on Mon May 12 09:40:02 2025
    Control: tag -1 pending

    Hello,

    Bug #1104964 in ironic reported by you has been fixed in the
    Git repository and is awaiting an upload. You can see the commit
    message below and you can check the diff of the fix at:

    https://salsa.debian.org/openstack-team/services/ironic/-/commit/959c8969a30e2b3899160b3d4584c06bb389b918

    ------------------------------------------------------------------------
    * CVE-2025-44021: Ironic fails to restrict paths used for file:// image URLs.
    Add upstream patch: OSSA-2025-001_Disallow+unsafe_image_file_paths.patch.
    (Closes: #1104964). ------------------------------------------------------------------------

    (this message was generated automatically)
    --
    Greetings

    https://bugs.debian.org/1104964

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Thomas Goirand@21:1/5 to All on Mon May 12 10:00:01 2025
    Control: tag -1 pending

    Hello,

    Bug #1104964 in ironic reported by you has been fixed in the
    Git repository and is awaiting an upload. You can see the commit
    message below and you can check the diff of the fix at:

    https://salsa.debian.org/openstack-team/services/ironic/-/commit/5c57a4de20bf27abd56df2e15add14ebaacf6d24

    ------------------------------------------------------------------------
    * CVE-2025-44021: Ironic fails to restrict paths used for file:// image URLs.
    Add upstream patch: OSSA-2025-001_Disallow+unsafe_image_file_paths.patch.
    (Closes: #1104964). ------------------------------------------------------------------------

    (this message was generated automatically)
    --
    Greetings

    https://bugs.debian.org/1104964

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)