Uploaded image for project: 'Red Hat OpenStack Services on OpenShift'
  1. Red Hat OpenStack Services on OpenShift
  2. OSPRH-18448

horizon 18.0: dashboard exposes sensitive S3 credentials in Glance Image Properties

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done-Errata
    • Icon: Critical Critical
    • rhos-18.0.11
    • rhos-18.0.0
    • horizon-operator
    • None
    • Pending Verification, Storage Integration Sprint 5
    • 2
    • Critical

      The Horizon dashboard is displaying sensitive information including S3 URLs and access keys in Glance image custom properties when using S3 backend storage.

      • this poses a significant security risk as end users can view internal service credentials through the web interface.

      This is due to Horizon using internal endpoints instead of public endpoints to communicate with OpenStack services

      Current configuration

      OPENSTACK_ENDPOINT_TYPE = "internalURL"

      Expected configuration

      OPENSTACK_ENDPOINT_TYPE = "publicURL"

              fpantano@redhat.com Francesco Pantano
              omcgonag@redhat.com Owen McGonagle
              Jan Jasek Jan Jasek
              rhos-dfg-ui
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: