[PATCH] [CVE-2024-48916] rgw/sts: fix to disallow unsupported JWT algorithms while...
authorPritha Srivastava <prsrivas@redhat.com>
Tue, 5 Nov 2024 06:33:00 +0000 (12:03 +0530)
committerSalvatore Bonaccorso <carnil@debian.org>
Sat, 16 May 2026 12:52:24 +0000 (14:52 +0200)
commitb14096665e593dc4074a4ecffa045386eee4931d
tree52eebd4c18264bcd6ebd47469eee4861c3b60060
parent2e540a10b12c03ea22ea7091e40bd1f2427d90c0
[PATCH] [CVE-2024-48916] rgw/sts: fix to disallow unsupported JWT algorithms while authenticating AssumeRoleWithWebIdentity using JWT obtained from an external IDP.

fixes: https://tracker.ceph.com/issues/68836

Signed-off-by: Pritha Srivastava <prsrivas@redhat.com>
Gbp-Pq: Name CVE-2024-48916.patch
src/rgw/rgw_rest_sts.cc