http_trace is enabled and has security risk in httpd
Bug #1705160 reported by
Jeffrey Zhang
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
kolla-ansible |
Fix Released
|
Undecided
|
Jeffrey Zhang | ||
Ocata |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
Need disable http trace feature in all containers running httpd
more info please check https:/
Changed in kolla-ansible: | |
milestone: | none → pike-3 |
description: | updated |
Changed in kolla-ansible: | |
assignee: | nobody → Jeffrey Zhang (jeffrey4l) |
To post a comment you must log in.
Reviewed: https:/ /review. openstack. org/485014 /git.openstack. org/cgit/ openstack/ kolla-ansible/ commit/ ?id=f5dd178fc53 4c4585fa7168ca0 649c684ff869b4
Committed: https:/
Submitter: Jenkins
Branch: master
commit f5dd178fc534c45 85fa7168ca0649c 684ff869b4
Author: Jeffrey Zhang <email address hidden>
Date: Wed Jul 19 10:52:41 2017 +0800
Disable trace for all containers running httpd
Trace method is enabled in default for httpd. There is security risk
with trace enabled. So disable it in default. more info please check[0].
[0] https:/ /security. stackexchange. com/a/7711
Change-Id: I4496a6d058d88e 1abfb210085f189 e7a610e0362
Closes-Bug: #1705160