service No-VNC (port 6080) doesn't require authentication
Bug #1447679 reported by
Jeremy Stanley
This bug affects 5 people
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Compute (nova) |
Confirmed
|
Medium
|
Unassigned | ||
OpenStack Security Advisory |
Won't Fix
|
Undecided
|
Unassigned |
Bug Description
Reported via private E-mail from Anass ANNOUR:
I found that the service No-VNC (port 6080) doesn't require authentication, if you know the URL (ex: http://
Changed in ossa: | |
status: | Incomplete → Won't Fix |
information type: | Private Security → Public |
tags: | added: security |
Changed in nova: | |
assignee: | Tony Breeds (o-tony) → Michael Still (mikalstill) |
Changed in nova: | |
assignee: | Michael Still (mikalstill) → nobody |
status: | In Progress → Confirmed |
To post a comment you must log in.
Since this report concerns a possible security risk, an incomplete security advisory task has been added while the core security reviewers for the affected project or projects confirm the bug and discuss the scope of any vulnerability along with potential solutions.