pybind/ceph_volume_client: Disallow authorize auth_id
authorRamana Raja <rraja@redhat.com>
Wed, 25 Nov 2020 11:14:35 +0000 (16:44 +0530)
committerBastien Roucariès <rouca@debian.org>
Sat, 21 Oct 2023 16:42:26 +0000 (17:42 +0100)
commitee2735975df967550b9496d71e7b50016de98b6f
tree095ba05de45f4a873134ec82f100cdc867847f5a
parent4b33f6dc7179fc260fd6e5eeba3eef0308af147f
pybind/ceph_volume_client: Disallow authorize auth_id

This patch disallow the ceph_volume_client to authorize the auth_id
which is not created by ceph_volume_client. Those auth_ids could be
created by other means for other use cases which should not be modified
by ceph_volume_client.

Fixes: https://tracker.ceph.com/issues/48555
Signed-off-by: Ramana Raja <rraja@redhat.com>
Signed-off-by: Kotresh HR <khiremat@redhat.com>
(cherry picked from commit 3a85d2d04028a323952a31d18cdbefb710be2e2b)

Origin: upstream, https://github.com/ceph/ceph/commit/1de5caf2da9b06aa4f363f9706c693213a6ee59f

Gbp-Pq: Name CVE-2020-27781-2.patch
src/pybind/ceph_volume_client.py