-
Bug
-
Resolution: Done-Errata
-
Normal
-
None
-
None
-
1
-
False
-
-
False
-
?
-
osp-director-operator-container-1.3.1-21
-
None
-
Release Note Not Required
-
-
-
Moderate
Security scanner will alert on HTTP trace enabled.
To Reproduce Steps to reproduce the behavior:
HTTP TRACE is allowed from OSPDO provisioner server.
Expected behavior
TraceEnable Off in httpd config
Bug impact
Security issue as defined by the scanner
Known workaround
None; it seems the operator will revert any manual config
- is cloned by
-
OSPRH-14672 OpenStackProvisionServer should not allow HTTP TRACE
-
- Closed
-
- links to
-
RHBA-2025:147775 Updated Red Hat OpenStack Platform 17.1 director Operator container images
- mentioned on
(2 mentioned on)