I've switched this report to a normal public bug and added a "won't fix" security advisory task to indicate that it's not something we'll be publishing an advisory about.
Note that the line referred to in the script is prefaced with a TODO comment pointing out pretty much exactly the same concern as was raised here.
I've switched this report to a normal public bug and added a "won't fix" security advisory task to indicate that it's not something we'll be publishing an advisory about.
Note that the line referred to in the script is prefaced with a TODO comment pointing out pretty much exactly the same concern as was raised here.
The VMT is treating this as a class D report (security hardening opportunity) per our taxonomy: https:/ /security. openstack. org/vmt- process. html#report- taxonomy