Comment 10 for bug 1254619

Revision history for this message
Jeremy Stanley (fungi) wrote : Re: ExternalDefault authentication plugin only considers leftmost part of the REMOTE_USER splited by "@"

For embargoed security vulnerabilities, a vulnerability management team member will end up submitting the patches to fix it in all affected branches at the time we release an accompanying advisory. When we do that, we generally set the Closes-Bug header in each commit message accordingly.

But that's jumping ahead a bit... first we need Keystone security reviewers to confirm the reported vulnerability and look at any proposed patches to address it (which should only be distributed by attaching them to this bug, if they agree that it should remain embargoed).