-
Bug
-
Resolution: Done-Errata
-
Critical
-
rhos-18.0.0
-
None
-
2
-
False
-
-
False
-
?
-
horizon-operator-container-1.0.13-5
-
None
-
-
-
-
Pending Verification, Storage Integration Sprint 5
-
2
-
Critical
The Horizon dashboard is displaying sensitive information including S3 URLs and access keys in Glance image custom properties when using S3 backend storage.
- this poses a significant security risk as end users can view internal service credentials through the web interface.
This is due to Horizon using internal endpoints instead of public endpoints to communicate with OpenStack services
Current configuration
OPENSTACK_ENDPOINT_TYPE = "internalURL"
Expected configuration
OPENSTACK_ENDPOINT_TYPE = "publicURL"
- links to
-
RHBA-2025:153488 Control plane Operators for RHOSO 18.0.11.