* CVE-2020-13223 Description: "core: Proxy environment variables are now redacted before being logged, in case the URLs include a username:password." PR: https://github.com/hashicorp/vault/pull/9022 * CVE-2020-12757 Description: "secrets/gcp: Fix a regression in 1.4.0 where the system TTLs were being used instead of the configured backend TTLs for dynamic service accounts." PR: https://github.com/hashicorp/vault-plugin-secrets-gcp/pull/85
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=d4d78ad8a53af7da57f8995560480724a77c327a commit d4d78ad8a53af7da57f8995560480724a77c327a Author: Zac Medico <zmedico@gentoo.org> AuthorDate: 2020-06-11 03:55:16 +0000 Commit: Zac Medico <zmedico@gentoo.org> CommitDate: 2020-06-11 03:55:41 +0000 app-admin/vault: Bump to version 1.4.2 (bug 727660) Bug: https://bugs.gentoo.org/727660 Package-Manager: Portage-2.3.100, Repoman-2.3.22 Signed-off-by: Zac Medico <zmedico@gentoo.org> app-admin/vault/Manifest | 2 ++ app-admin/vault/vault-1.4.2.ebuild | 72 ++++++++++++++++++++++++++++++++++++++ 2 files changed, 74 insertions(+)
@maintainer(s), let us know when ready for stabilisation, or call yourself
@maintainer(s), I'll add CC-ARCHES now if no objections.
amd64 stable. Maintainer(s), please cleanup. Security, please vote.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=0c571fb781d73c1b773e3e033cf192be29de1ab8 commit 0c571fb781d73c1b773e3e033cf192be29de1ab8 Author: William Hubbs <williamh@gentoo.org> AuthorDate: 2020-06-25 20:08:04 +0000 Commit: William Hubbs <williamh@gentoo.org> CommitDate: 2020-06-25 20:17:06 +0000 app-admin/vault: remove old Bug: https://bugs.gentoo.org/727660 Signed-off-by: William Hubbs <williamh@gentoo.org> app-admin/vault/Manifest | 2 -- app-admin/vault/vault-1.4.0.ebuild | 72 -------------------------------------- 2 files changed, 74 deletions(-)
Thanks!
Unable to check for sanity: > no match for package: =app-admin/vault-1.4.2
GLSA vote: no! Closing.