Running Flask server in debug mode may be a security issue
Bug #1506419 reported by
Dmitry Tantsur
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Ironic Inspector |
Fix Released
|
High
|
Dmitry Tantsur | ||
Kilo |
Fix Released
|
High
|
Dmitry Tantsur | ||
Liberty |
Fix Released
|
High
|
Dmitry Tantsur | ||
Mitaka |
Fix Released
|
High
|
Dmitry Tantsur | ||
OpenStack Security Advisory |
Won't Fix
|
Undecided
|
Unassigned |
Bug Description
A lot of people default to running their servers in debug mode. While handy for getting the full logs, in our case it will also allow access to Flask console, which may pose a security risk. We need a separate option for this.
CVE References
To post a comment you must log in.
Fix proposed to branch: master /review. openstack. org/235258
Review: https:/