[#322040] p10 EPERM glpi.git=9.5.13-alt1

Girar awaiter (zidex) girar-builder at altlinux.org
Sat May 27 20:40:03 MSK 2023


https://git.altlinux.org/tasks/322040/logs/events.1.1.log

subtask  name  aarch64  armh  i586  ppc64le  x86_64
   #100  glpi     1:27  2:11    58     1:39      55

2023-May-27 17:34:04 :: task #322040 for p10 started by zidex:
2023-May-27 17:34:04 :: message: security_fix
#100 build 9.5.13-alt1 from /people/zidex/packages/glpi.git fetched at 2023-May-27 17:33:26
2023-May-27 17:34:06 :: [ppc64le] #100 glpi.git 9.5.13-alt1: build start
2023-May-27 17:34:06 :: [aarch64] #100 glpi.git 9.5.13-alt1: build start
2023-May-27 17:34:06 :: [armh] #100 glpi.git 9.5.13-alt1: build start
2023-May-27 17:34:06 :: [x86_64] #100 glpi.git 9.5.13-alt1: build start
2023-May-27 17:34:06 :: [i586] #100 glpi.git 9.5.13-alt1: build start
2023-May-27 17:35:01 :: [x86_64] #100 glpi.git 9.5.13-alt1: build OK
2023-May-27 17:35:04 :: [i586] #100 glpi.git 9.5.13-alt1: build OK
2023-May-27 17:35:33 :: [aarch64] #100 glpi.git 9.5.13-alt1: build OK
2023-May-27 17:35:45 :: [ppc64le] #100 glpi.git 9.5.13-alt1: build OK
2023-May-27 17:36:17 :: [armh] #100 glpi.git 9.5.13-alt1: build OK
2023-May-27 17:36:37 :: #100: glpi.git 9.5.13-alt1: build check OK
2023-May-27 17:36:39 :: build check OK
2023-May-27 17:36:57 :: noarch check OK
2023-May-27 17:36:59 :: plan: src +1 -1 =18078, noarch +3 -3 =16585
#100 glpi 9.5.12-alt1 -> 9.5.13-alt1
 Sat May 27 2023 Pavel Zilke <zidex at altlinux> 9.5.13-alt1
 - New version 9.5.13
 - This release fixes several security issues that have been recently discovered. Update is recommended!
 - Security fixes:
  + CVE-2023-28632 : Account takeover by authenticated user
  + CVE-2023-28838 : SQL injection through dynamic reports
  + CVE-2023-28852 : Stored XSS through dashboard administration
  + CVE-2023-28636 : Stored XSS on external links
  + CVE-2023-28639 : Reflected XSS in search pages
  + CVE-2023-28634 : Privilege Escalation from technician to super-admin
 [...]
2023-May-27 17:36:59 :: glpi: mentions vulnerabilities: CVE-2023-28632 CVE-2023-28838 CVE-2023-28852 CVE-2023-28636 CVE-2023-28639 CVE-2023-28634 CVE-2023-28633
2023-May-27 17:37:23 :: patched apt indices
2023-May-27 17:37:35 :: created next repo
2023-May-27 17:37:43 :: duplicate provides check OK
2023-May-27 17:38:18 :: dependencies check OK
2023-May-27 17:38:31 :: [x86_64] #100 glpi: install check OK
2023-May-27 17:38:32 :: [i586] #100 glpi: install check OK
2023-May-27 17:38:39 :: [x86_64] #100 glpi-apache2: install check OK
2023-May-27 17:38:40 :: [i586] #100 glpi-apache2: install check OK
2023-May-27 17:38:42 :: [aarch64] #100 glpi: install check OK
2023-May-27 17:38:45 :: [ppc64le] #100 glpi: install check OK
2023-May-27 17:38:46 :: [x86_64] #100 glpi-php7: install check OK
2023-May-27 17:38:48 :: [i586] #100 glpi-php7: install check OK
2023-May-27 17:38:54 :: [armh] #100 glpi: install check OK
2023-May-27 17:38:54 :: [aarch64] #100 glpi-apache2: install check OK
2023-May-27 17:39:01 :: [ppc64le] #100 glpi-apache2: install check OK
2023-May-27 17:39:07 :: [aarch64] #100 glpi-php7: install check OK
2023-May-27 17:39:14 :: [armh] #100 glpi-apache2: install check OK
2023-May-27 17:39:16 :: [ppc64le] #100 glpi-php7: install check OK
2023-May-27 17:39:33 :: [armh] #100 glpi-php7: install check OK
2023-May-27 17:39:34 :: gears inheritance check OK
2023-May-27 17:39:35 :: srpm inheritance check OK
girar-check-perms: access to glpi DENIED for zidex: project `glpi' is not listed in the acl file for repository `p10', and the policy for such projects in `p10' is to deny
check-subtask-perms: #100: glpi: needs approvals from members of @maint and @tester groups
2023-May-27 17:39:36 :: acl check FAILED
2023-May-27 17:39:53 :: created contents_index files
2023-May-27 17:40:01 :: created hash files: noarch src
2023-May-27 17:40:03 :: task #322040 for p10 EPERM


More information about the Sisyphus-incominger mailing list