[15:29] <fungi> a new week, a new vuln... looks like apache announced cve-2021-44224 to oss-security today, though i don't see it in the ubuntu cve tracker yet. the bit where an attacker could coerce mod_proxy to connect to a local unix socket is particularly worrisome
[15:45] <mdeslaur> ugh
[15:51] <teward> stupid q but when did the CVE get announced?  Might not have yet been synced up into the tracker yet.
[15:51] <teward> just stating the obvious
[15:51] <teward> in other news: hell week #2
[15:51] <teward> (except that none of the APaches I use or control or touch are affected so yay?)
[15:51] <mdeslaur> we need to manually add CVEs, I'm adding them now
[16:05] <fungi> thanks! i see it on the tracker now
[16:15] <mdeslaur> well, the mod_proxy issue isn't an easy backport, so it's not going to be soon