-
Bug
-
Resolution: Done
-
Normal
-
None
-
None
-
1
-
False
-
-
False
-
No Docs Impact
-
openstack-operator-container-1.0.8-13
-
None
-
-
Bug Fix
-
Done
-
Regression Only
-
-
-
Moderate
Security scanner will alert on HTTP trace enabled.
To Reproduce Steps to reproduce the behavior:
HTTP TRACE is allowed from OSPDO provisioner server.
Expected behavior
TraceEnable Off in httpd config
Bug impact
Security issue as defined by the scanner
Known workaround
None; it seems the operator will revert any manual config
- clones
-
OSPRH-14473 [17.1 OSPDO] - OpenStackProvisionServer should not allow HTTP TRACE
-
- Closed
-
- links to
- mentioned on