[PATCH] [CVE-2024-48916] rgw/sts: fix to disallow unsupported JWT algorithms while...
authorPritha Srivastava <prsrivas@redhat.com>
Tue, 5 Nov 2024 06:33:00 +0000 (12:03 +0530)
committerDaniel Baumann <daniel@debian.org>
Wed, 4 Dec 2024 05:46:17 +0000 (06:46 +0100)
commit452d14bb2433d12a194bcd36d3a2c4702dbbcf16
tree5173164078b45546273a5a6313df851aea920641
parent1e7a7157ad64286d729b87854ad647c7d76ec7de
[PATCH] [CVE-2024-48916] rgw/sts: fix to disallow unsupported JWT algorithms while authenticating AssumeRoleWithWebIdentity using JWT obtained from an external IDP.

fixes: https://tracker.ceph.com/issues/68836

Signed-off-by: Pritha Srivastava <prsrivas@redhat.com>
Gbp-Pq: Name CVE-2024-48916.patch
src/rgw/rgw_rest_sts.cc