Public bug reported:

The openstack-dashboard /server-status page is accessible by default.
While useful for some, the existence of the this page may be considered
a vulnerability.

The workaround for this would be to execute 'a2dismod status && service
restart apache2' on the openstack-dashboard unit.

Suggest making this a charm option, enabled by default.

** Affects: openstack-dashboard (Ubuntu)
     Importance: Undecided
         Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1710917

Title:
  ability to disable apache mod_status

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/openstack-dashboard/+bug/1710917/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to