[go: nahoru, domu]

Page MenuHomePhabricator

sbassett (Scott Bassett)
Staff Security EngineerAdministrator

Today

  • Clear sailing ahead.

Tomorrow

  • Clear sailing ahead.

Friday

  • Clear sailing ahead.

User Details

User Since
Sep 12 2018, 3:52 PM (310 w, 6 h)
Roles
Administrator
Availability
Available
IRC Nick
sbassett
LDAP User
SBassett
MediaWiki User
SBassett (WMF) [ Global Accounts ]

Member of the Security-Team. My user-sbassett board should be fairly up-to-date, though we also track some other work within Asana these days.

Recent Activity

Yesterday

sbassett set Author Affiliation to community on T372211: Various XSSes found in Cargo.
Tue, Aug 20, 1:58 PM · MediaWiki-extensions-Cargo, Vuln-XSS, affects-Miraheze, Security, Security-Team

Mon, Aug 19

sbassett updated the task description for T372829: Offboard Hal Triedman from the Security Team.
Mon, Aug 19, 9:00 PM · Security-Team
sbassett updated subscribers of T372829: Offboard Hal Triedman from the Security Team.
Mon, Aug 19, 8:59 PM · Security-Team
sbassett updated subscribers of T372829: Offboard Hal Triedman from the Security Team.
Mon, Aug 19, 8:59 PM · Security-Team
sbassett updated the task description for T372829: Offboard Hal Triedman from the Security Team.
Mon, Aug 19, 8:59 PM · Security-Team
sbassett updated the task description for T372829: Offboard Hal Triedman from the Security Team.
Mon, Aug 19, 8:58 PM · Security-Team
sbassett updated the task description for T372829: Offboard Hal Triedman from the Security Team.
Mon, Aug 19, 8:58 PM · Security-Team
sbassett created T372829: Offboard Hal Triedman from the Security Team.
Mon, Aug 19, 8:55 PM · Security-Team
sbassett added a comment to T372825: Unexpected helmfile changes when attempting a k8s deployment for a miscweb site.

Just FYI: I applied all of the changes to staging, codfw and eqiad, but only deployed to security-landing-page: https://sal.toolforge.org/log/4GppbJEBFFSCpsJzN8fC

Mon, Aug 19, 8:53 PM · serviceops
sbassett moved T372570: Username links are broken on security.wikimedia.org from In Progress to Our Part Is Done on the Security-Team board.
Mon, Aug 19, 8:53 PM · user-sbassett, SecTeam-Processed, Security-Team
sbassett moved T372570: Username links are broken on security.wikimedia.org from Backlog to Done on the user-sbassett board.
Mon, Aug 19, 8:52 PM · user-sbassett, SecTeam-Processed, Security-Team
sbassett closed T372570: Username links are broken on security.wikimedia.org as Resolved.
Mon, Aug 19, 8:52 PM · user-sbassett, SecTeam-Processed, Security-Team
sbassett updated the task description for T372825: Unexpected helmfile changes when attempting a k8s deployment for a miscweb site.
Mon, Aug 19, 8:04 PM · serviceops
sbassett created T372825: Unexpected helmfile changes when attempting a k8s deployment for a miscweb site.
Mon, Aug 19, 7:59 PM · serviceops
sbassett moved T371814: [EPIC] Security Dashboard from Backlog to In Progress on the user-sbassett board.
Mon, Aug 19, 3:23 PM · SecTeam-Processed, Universal Security Dashboard, user-sbassett, Epic, Security, Security-Team
sbassett moved T371820: Investigate stand-alone CI and job-runner FOSS solutions from Backlog to In Progress on the user-sbassett board.
Mon, Aug 19, 3:23 PM · SecTeam-Processed, Universal Security Dashboard, user-sbassett, Security, Security-Team
sbassett moved T371819: Investigate git repository management and caching solution from Backlog to In Progress on the user-sbassett board.
Mon, Aug 19, 3:23 PM · SecTeam-Processed, Universal Security Dashboard, user-sbassett, Security, Security-Team
sbassett added a project to T372572: Migrate the help key to help-raw within phan-taint-check plugin: SecTeam-Processed.
Mon, Aug 19, 3:03 PM · SecTeam-Processed, user-sbassett, Security, phan-taint-check-plugin
sbassett closed T372572: Migrate the help key to help-raw within phan-taint-check plugin as Resolved.
Mon, Aug 19, 3:03 PM · SecTeam-Processed, user-sbassett, Security, phan-taint-check-plugin

Fri, Aug 16

sbassett added a comment to T372527: Deploy CommunityRequests to Meta.

We're aiming for mid-late September, as discussed at T365525 and outlined at T366194. Does that work for you?

Fri, Aug 16, 4:49 PM · Patch-For-Review, MediaWiki-extensions-CommunityRequests

Thu, Aug 15

sbassett added a comment to T364302: Complete the Mitre CNA Partner Process for the Wikimedia Foundation .

Eh, we could probably just replace "Start" with "Complete" in the task title.

Thu, Aug 15, 10:26 PM · Security-Team
sbassett moved T372572: Migrate the help key to help-raw within phan-taint-check plugin from Backlog to Issues in MediaWiki code on the phan-taint-check-plugin board.
Thu, Aug 15, 3:58 PM · SecTeam-Processed, user-sbassett, Security, phan-taint-check-plugin
sbassett changed the status of T372572: Migrate the help key to help-raw within phan-taint-check plugin from Open to In Progress.
Thu, Aug 15, 3:58 PM · SecTeam-Processed, user-sbassett, Security, phan-taint-check-plugin
sbassett moved T372572: Migrate the help key to help-raw within phan-taint-check plugin from Backlog to In Progress on the user-sbassett board.
Thu, Aug 15, 3:58 PM · SecTeam-Processed, user-sbassett, Security, phan-taint-check-plugin
sbassett added a comment to T356971: Rename help key to help-raw in HTMLForm and deprecate old key name.

We also need a patch to phan-taint-check to make sure the bew keynane is marked as xss risk.

Thu, Aug 15, 3:42 PM · MW-1.43-notes (1.43.0-wmf.18; 2024-08-13), good first task, SecTeam-Processed, MediaWiki-HTMLForm, Vuln-XSS, Security
sbassett updated the task description for T372572: Migrate the help key to help-raw within phan-taint-check plugin.
Thu, Aug 15, 3:41 PM · SecTeam-Processed, user-sbassett, Security, phan-taint-check-plugin
sbassett updated the task description for T372572: Migrate the help key to help-raw within phan-taint-check plugin.
Thu, Aug 15, 3:41 PM · SecTeam-Processed, user-sbassett, Security, phan-taint-check-plugin
sbassett added a project to T372572: Migrate the help key to help-raw within phan-taint-check plugin: Security.
Thu, Aug 15, 3:40 PM · SecTeam-Processed, user-sbassett, Security, phan-taint-check-plugin
sbassett created T372572: Migrate the help key to help-raw within phan-taint-check plugin.
Thu, Aug 15, 3:39 PM · SecTeam-Processed, user-sbassett, Security, phan-taint-check-plugin
sbassett updated subscribers of T372527: Deploy CommunityRequests to Meta.

Hi @sbassett — we're looking to start the process of deploying this to the beta cluster in preparation for the goal of this task (production deployment), and just wanted to check that we're okay to do so per your above message in T365525: Application Security Review Request : CommunityRequests Extension

Thu, Aug 15, 3:19 PM · Patch-For-Review, MediaWiki-extensions-CommunityRequests
sbassett changed the status of T372570: Username links are broken on security.wikimedia.org from Open to In Progress.
Thu, Aug 15, 3:14 PM · user-sbassett, SecTeam-Processed, Security-Team
sbassett created T372570: Username links are broken on security.wikimedia.org.
Thu, Aug 15, 3:13 PM · user-sbassett, SecTeam-Processed, Security-Team
sbassett set Author Affiliation to product on T358123: Open Redirect in oauth login.
Thu, Aug 15, 2:48 PM · Moderator-Tools-Team (Kanban), Essential-Work, SecTeam-Processed, The-Wikipedia-Library, Security-Team, Security
sbassett moved T358123: Open Redirect in oauth login from Watching to Our Part Is Done on the Security-Team board.
Thu, Aug 15, 2:47 PM · Moderator-Tools-Team (Kanban), Essential-Work, SecTeam-Processed, The-Wikipedia-Library, Security-Team, Security
sbassett removed a project from T370693: Special:Preferences CSRF vulnerability allows attacker to change an account's Real Name.: Vuln-CSRF.
Thu, Aug 15, 2:44 PM · SecTeam-Processed, MediaWiki-Core-Preferences, Security, Security-Team
sbassett triaged T370693: Special:Preferences CSRF vulnerability allows attacker to change an account's Real Name. as Low priority.
Thu, Aug 15, 2:44 PM · SecTeam-Processed, MediaWiki-Core-Preferences, Security, Security-Team
sbassett added a comment to T364302: Complete the Mitre CNA Partner Process for the Wikimedia Foundation .

Sounds good. Is this resolvable now?

Thu, Aug 15, 2:44 PM · Security-Team
sbassett moved T372022: Decide if AccountVanishRequests locks should be shown by StewardBot from Incoming to Watching on the Security-Team board.
Thu, Aug 15, 2:42 PM · SecTeam-Processed, Security-Team, Stewards-and-global-tools, stewardbots
sbassett added a project to T234987: Increase pbkdf2 parameter strengths (2019): SecTeam-Processed.
Thu, Aug 15, 2:41 PM · SecTeam-Processed, Security, Wikimedia-Site-requests, MediaWiki-Core-AuthManager
sbassett added a project to T366005: Remove docroot/wikimediafoundation.org/ folder from mediawiki-config: Infrastructure-Foundations.

Tagging Infrastructure-Foundations to get a definitive opinion on the matrix/server file mentioned above. I'm not sure why that would still be necessary when wikimediafoundation.org is a WP site fully-hosted at VIP/Automattic these days, but admittedly I don't have the ops knowledge to know for sure.

Thu, Aug 15, 2:39 PM · Infrastructure-Foundations, Patch-For-Review, SecTeam-Processed, Security-Team, Wikimedia-Apache-configuration, Security
sbassett closed T370693: Special:Preferences CSRF vulnerability allows attacker to change an account's Real Name. as Invalid.
Thu, Aug 15, 2:32 PM · SecTeam-Processed, MediaWiki-Core-Preferences, Security, Security-Team
sbassett moved T371569: SMTP smuggling vulnerability report from Watching to Our Part Is Done on the Security-Team board.
Thu, Aug 15, 2:30 PM · SecTeam-Processed, Vuln-VulnComponent, Infrastructure-Foundations, Security, Security-Team
sbassett changed the visibility for T371569: SMTP smuggling vulnerability report.
Thu, Aug 15, 2:30 PM · SecTeam-Processed, Vuln-VulnComponent, Infrastructure-Foundations, Security, Security-Team
sbassett triaged T314148: Investigate: Spur as an additional data source for IPInfo as Low priority.
Thu, Aug 15, 2:27 PM · Anti-Harassment, SecTeam-Processed, Security, IP Info

Thu, Aug 8

sbassett added a project to T372022: Decide if AccountVanishRequests locks should be shown by StewardBot: Security-Team.
Thu, Aug 8, 4:19 PM · SecTeam-Processed, Security-Team, Stewards-and-global-tools, stewardbots
sbassett set Author Affiliation to tech on T372026: GitLab Security Release: 17.2.2, 17.1.4, 17.0.6.
Thu, Aug 8, 4:19 PM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, Security
sbassett edited projects for T372026: GitLab Security Release: 17.2.2, 17.1.4, 17.0.6, added: SecTeam-Processed, Vuln-VulnComponent; removed Security-Team.
Thu, Aug 8, 4:18 PM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, Security

Wed, Aug 7

sbassett moved T369950: Application Security Review Request : Chart extension (placeholder) from Back Orders to Upcoming Quarter Planning Queue on the secscrum board.
Wed, Aug 7, 7:06 PM · Charts, secscrum, Security, Application Security Reviews
sbassett set Author Affiliation to tech on T370973: GitLab Security Release 17.2.1, 17.1.3, 17.0.5.
Wed, Aug 7, 6:52 PM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, GitLab, Security
sbassett set Author Affiliation to tech on T371953: GitLab Security Release: GitLab Patch Release: 17.2.1, 17.1.3, 17.0.5 .
Wed, Aug 7, 6:52 PM · Vuln-VulnComponent, SecTeam-Processed, GitLab (Infrastructure), collaboration-services, Security
sbassett edited projects for T371953: GitLab Security Release: GitLab Patch Release: 17.2.1, 17.1.3, 17.0.5 , added: SecTeam-Processed, Vuln-VulnComponent; removed Security-Team.
Wed, Aug 7, 6:51 PM · Vuln-VulnComponent, SecTeam-Processed, GitLab (Infrastructure), collaboration-services, Security

Tue, Aug 6

sbassett awarded T371847: +2 for Bhsd in mediawiki/extensions/CodeMirror a Like token.
Tue, Aug 6, 4:44 PM · MediaWiki-extensions-CodeMirror, Community-Tech, Gerrit-Privilege-Requests

Mon, Aug 5

sbassett added a comment to T370693: Special:Preferences CSRF vulnerability allows attacker to change an account's Real Name..

Any issues with making this task public, as I'm fairly certain we've confirmed that the original, reported issue is a false positive.

Mon, Aug 5, 4:18 PM · SecTeam-Processed, MediaWiki-Core-Preferences, Security, Security-Team
sbassett moved T371569: SMTP smuggling vulnerability report from Incoming to Watching on the Security-Team board.
Mon, Aug 5, 4:13 PM · SecTeam-Processed, Vuln-VulnComponent, Infrastructure-Foundations, Security, Security-Team
sbassett moved T370693: Special:Preferences CSRF vulnerability allows attacker to change an account's Real Name. from Incoming to Watching on the Security-Team board.
Mon, Aug 5, 4:12 PM · SecTeam-Processed, MediaWiki-Core-Preferences, Security, Security-Team
sbassett moved T371819: Investigate git repository management and caching solution from Incoming to In Progress on the Security-Team board.
Mon, Aug 5, 4:07 PM · SecTeam-Processed, Universal Security Dashboard, user-sbassett, Security, Security-Team
sbassett moved T371821: Investigate reporting options for various tools, tabular CLI reports, etc. from Incoming to In Progress on the Security-Team board.
Mon, Aug 5, 4:07 PM · SecTeam-Processed, Universal Security Dashboard, Security, Security-Team
sbassett moved T371814: [EPIC] Security Dashboard from Incoming to In Progress on the Security-Team board.
Mon, Aug 5, 4:07 PM · SecTeam-Processed, Universal Security Dashboard, user-sbassett, Epic, Security, Security-Team
sbassett moved T371820: Investigate stand-alone CI and job-runner FOSS solutions from Incoming to In Progress on the Security-Team board.
Mon, Aug 5, 4:06 PM · SecTeam-Processed, Universal Security Dashboard, user-sbassett, Security, Security-Team
sbassett moved T371818: Investigate puppet configuration/profile for a stand-alone python/django application under wmcs bookworm instance from Incoming to In Progress on the Security-Team board.
Mon, Aug 5, 4:03 PM · SecTeam-Processed, Universal Security Dashboard, Security, Security-Team
sbassett created T371821: Investigate reporting options for various tools, tabular CLI reports, etc..
Mon, Aug 5, 3:41 PM · SecTeam-Processed, Universal Security Dashboard, Security, Security-Team
sbassett created T371820: Investigate stand-alone CI and job-runner FOSS solutions.
Mon, Aug 5, 3:36 PM · SecTeam-Processed, Universal Security Dashboard, user-sbassett, Security, Security-Team
sbassett created T371819: Investigate git repository management and caching solution.
Mon, Aug 5, 3:33 PM · SecTeam-Processed, Universal Security Dashboard, user-sbassett, Security, Security-Team
sbassett created T371818: Investigate puppet configuration/profile for a stand-alone python/django application under wmcs bookworm instance.
Mon, Aug 5, 3:30 PM · SecTeam-Processed, Universal Security Dashboard, Security, Security-Team
sbassett moved T371817: Create development environment instance for security dashboard under wikimedia cloud services from Backlog to Done on the Universal Security Dashboard board.
Mon, Aug 5, 3:26 PM · Universal Security Dashboard, user-sbassett, Security, Security-Team
sbassett closed T371817: Create development environment instance for security dashboard under wikimedia cloud services as Resolved.
Mon, Aug 5, 3:26 PM · Universal Security Dashboard, user-sbassett, Security, Security-Team
sbassett moved T371817: Create development environment instance for security dashboard under wikimedia cloud services from Backlog to Done on the user-sbassett board.
Mon, Aug 5, 3:26 PM · Universal Security Dashboard, user-sbassett, Security, Security-Team
sbassett closed T371817: Create development environment instance for security dashboard under wikimedia cloud services, a subtask of T371814: [EPIC] Security Dashboard, as Resolved.
Mon, Aug 5, 3:26 PM · SecTeam-Processed, Universal Security Dashboard, user-sbassett, Epic, Security, Security-Team
sbassett created T371817: Create development environment instance for security dashboard under wikimedia cloud services.
Mon, Aug 5, 3:25 PM · Universal Security Dashboard, user-sbassett, Security, Security-Team
sbassett added a project to T371814: [EPIC] Security Dashboard: Universal Security Dashboard.
Mon, Aug 5, 3:18 PM · SecTeam-Processed, Universal Security Dashboard, user-sbassett, Epic, Security, Security-Team
sbassett created Universal Security Dashboard.
Mon, Aug 5, 3:17 PM
sbassett added a project to T371814: [EPIC] Security Dashboard: user-sbassett.
Mon, Aug 5, 3:13 PM · SecTeam-Processed, Universal Security Dashboard, user-sbassett, Epic, Security, Security-Team
sbassett updated the task description for T371814: [EPIC] Security Dashboard.
Mon, Aug 5, 3:13 PM · SecTeam-Processed, Universal Security Dashboard, user-sbassett, Epic, Security, Security-Team
sbassett created T371814: [EPIC] Security Dashboard.
Mon, Aug 5, 3:11 PM · SecTeam-Processed, Universal Security Dashboard, user-sbassett, Epic, Security, Security-Team
sbassett removed a project from T255208: Catalog and evaluate methods of analysis for Wikimedia captcha performance: user-sbassett.
Mon, Aug 5, 2:43 PM · observability, ConfirmEdit (CAPTCHA extension), Security-Team, Security

Sun, Aug 4

Pppery awarded T302640: Harden Special:Random and API:Random to automatically adjust in certain ways during on-wiki incidents a Dislike token.
Sun, Aug 4, 4:38 PM · SecTeam-Processed, MediaWiki-Action-API, MediaWiki-Special-pages, Security

Fri, Aug 2

sbassett added a comment to T371569: SMTP smuggling vulnerability report.

Our postfix servers have now been configured with the "long term fix", T370011, https://www.postfix.org/smtp-smuggling.html#back-ports

Our lists server has Exim4 4.96-15+deb12u4, which has a patch included to fix the attack vector according to https://security-tracker.debian.org/tracker/CVE-2023-51766

Fri, Aug 2, 3:56 PM · SecTeam-Processed, Vuln-VulnComponent, Infrastructure-Foundations, Security, Security-Team

Wed, Jul 31

sbassett added projects to T371569: SMTP smuggling vulnerability report: Infrastructure-Foundations, Vuln-VulnComponent.
Wed, Jul 31, 10:44 PM · SecTeam-Processed, Vuln-VulnComponent, Infrastructure-Foundations, Security, Security-Team
sbassett updated subscribers of T371569: SMTP smuggling vulnerability report.
Wed, Jul 31, 10:44 PM · SecTeam-Processed, Vuln-VulnComponent, Infrastructure-Foundations, Security, Security-Team
sbassett created T371569: SMTP smuggling vulnerability report.
Wed, Jul 31, 10:43 PM · SecTeam-Processed, Vuln-VulnComponent, Infrastructure-Foundations, Security, Security-Team
sbassett added a comment to T45646: "MediaWiki:Copyright" message allows raw HTML.
  • We could also make a site-wide configuration variable for "copyright is raw html", and default it to false, and set it to true only for german wikipedia. That would allow us to incrementally improve our security footing without necessarily breaking german wiki or third parties which might rely on this.
Wed, Jul 31, 10:13 PM · I18n, Security, MW-1.32-notes (WMF-deploy-2018-08-28 (1.32.0-wmf.19)), Vuln-XSS, MediaWiki-General
sbassett added a comment to T367995: Security Preview for shared login domain.

Do you mean the shared login domain specifically or the SUL3 project in general? (I'll file another security preview request about T363699: Determine and implement SUL 3 login handshake mechanism in a day or two, once I have PoC code. I think these are the two particularly security-sensitive parts of the project, the rest of the work is less interesting.)

Wed, Jul 31, 5:29 PM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS

Tue, Jul 30

sbassett triaged T371220: Need to delete unrelated etherpad as Medium priority.
Tue, Jul 30, 4:00 PM · Vuln-Infoleak, Privacy, collaboration-services, Security-Team, Security, Wikimedia-Etherpad
sbassett added projects to T371220: Need to delete unrelated etherpad: Privacy, Vuln-Infoleak.
Tue, Jul 30, 3:59 PM · Vuln-Infoleak, Privacy, collaboration-services, Security-Team, Security, Wikimedia-Etherpad
sbassett changed the status of T370867: security@wikimedia.org access required for tappof from Open to In Progress.
Tue, Jul 30, 3:45 PM · SecTeam-Processed, Security-Team
sbassett changed the status of T370850: Security Issue Access Request for (tappof) from Open to In Progress.
Tue, Jul 30, 3:45 PM · SecTeam-Processed, Security-Team, Security

Mon, Jul 29

sbassett closed T336556: XSS via Graph extension (still) as Invalid.
Mon, Jul 29, 11:48 PM · SecTeam-Processed, MediaWiki-extensions-Graph, Vuln-XSS, Security, Security-Team
sbassett closed T336556: XSS via Graph extension (still), a subtask of T334940: All Graphs broken on Wikimedia wikis (due to security issue T336556), as Invalid.
Mon, Jul 29, 11:48 PM · User-zeljkofilipin, Regression, User-notice, Tech Ambassadors & Translators, MediaWiki-extensions-Graph
sbassett moved T336556: XSS via Graph extension (still) from In Progress to Our Part Is Done on the Security-Team board.
Mon, Jul 29, 11:48 PM · SecTeam-Processed, MediaWiki-extensions-Graph, Vuln-XSS, Security, Security-Team
sbassett updated subscribers of T336556: XSS via Graph extension (still).

Can this be public? It sounds like these issues were fixed, and in any case, the graph extension is dead at this point.

Mon, Jul 29, 11:47 PM · SecTeam-Processed, MediaWiki-extensions-Graph, Vuln-XSS, Security, Security-Team

Fri, Jul 26

sbassett added a comment to T362774: Application Security Review Request : service-runner replacement: @tchin/service-utils.

Just quickly running semgrep supply-chain against these codebases, it found that wikimedia/service-runner@master had two dependency vulnerabilities with undetermined reachability and that wikimedia/service-template-node@master had two dependency vulnerabilities with undetermined reachability and one with confirmed reachability.

Fri, Jul 26, 5:56 PM · secscrum, Security, Application Security Reviews
sbassett added a comment to T370693: Special:Preferences CSRF vulnerability allows attacker to change an account's Real Name..

So in essence, I was able to prefil the form based on user parameters, but not save. At a glance, it looks like i succesfully did the attack, but when i reloaded the page, my malicious value went away.

Fri, Jul 26, 5:30 PM · SecTeam-Processed, MediaWiki-Core-Preferences, Security, Security-Team
sbassett added a project to T309772: npm audit reports several security issues with Service runner: Vuln-VulnComponent.
Fri, Jul 26, 1:47 PM · Vuln-VulnComponent, LPL Essential (LPL Essential 2024 Jul-Sep), MediaWiki-Engineering, CX-cxserver, Security, service-runner
sbassett added a comment to T368336: Select a chart library.

I'd also note that the Vega dependency was the primary reason we disabled ext:Graph (twice). And that while Vega's expressions layer has since been hardened, it likely still poses more risk for our use-cases than other options.

Fri, Jul 26, 1:45 PM · Charts (Sprint 1)

Thu, Jul 25

sbassett triaged T365144: Application Security Review Request : Quarto as Low priority.
Thu, Jul 25, 4:18 PM · Product-Analytics, secscrum, Security, Application Security Reviews
sbassett moved T365144: Application Security Review Request : Quarto from Waiting to Our Part Is Done on the secscrum board.
Thu, Jul 25, 4:18 PM · Product-Analytics, secscrum, Security, Application Security Reviews
sbassett updated subscribers of T370739: Figure out how a shellbox instance for the Chart extension would work.

@aude service-template-node is indeed quite dated and fairly unmaintained. And it would be difficult to recommend it for new projects, from a security perspective. Sadly, I don't think there has been consensus on a replacement option. It would be nice to consolidate around something as having a dozen new frameworks that essentially do the same thing is not ideal. You might want to reach out to @tchin as they have been working on at least one replacement option (T360924, T362774, et al).

Thu, Jul 25, 4:14 PM · Charts (Sprint 3), serviceops, SRE, Shellbox
sbassett set Author Affiliation to community on T326613: Database credentials for s51347 (fatg) publicly readable on Toolforge.
Thu, Jul 25, 4:10 PM · cloud-services-team (FY2023/2024-Q3-Q4), Vuln-Infoleak, SecTeam Discussion, Tools, Security
sbassett edited projects for T370973: GitLab Security Release 17.2.1, 17.1.3, 17.0.5, added: SecTeam-Processed, Vuln-VulnComponent; removed Security-Team.
Thu, Jul 25, 4:10 PM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, GitLab, Security

Wed, Jul 24

sbassett added a comment to T367995: Security Preview for shared login domain.

Hey @Tgr - I'd like to set up an initial threat-modeling/concept-review session (or two) for this work with you and any other relevant folks, this quarter. Are there any other technical folks that you're aware of who would likely be helpful during or interested in participating in such exercises? Thanks.

Wed, Jul 24, 4:20 PM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS