Comment 1 for bug 2021980

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package cinder - 2:22.0.0-0ubuntu4

---------------
cinder (2:22.0.0-0ubuntu4) mantic; urgency=medium

  * SECURITY UPDATE: Unauthorized File Access (LP: #2021980)
    - debian/patches/CVE-2023-2088-1.patch: Reject unsafe delete
      attachment calls.
    - debian/patches/CVE-2023-2088-2.patch: Doc: Improve service token.
    - CVE-2023-2088

 -- Corey Bryant <email address hidden> Fri, 26 May 2023 16:16:03 -0400