Location information still showing in calls to HEAD|GET /images/<ID>

Bug #860862 reported by Jay Pipes
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Glance
Fix Released
High
Jay Pipes
Diablo
Fix Released
Undecided
Unassigned

Bug Description

X-Image-Meta-Location header is still leaking security creds for the show() and meta() methods of the images controller!

Tags: backport
Jay Pipes (jaypipes)
Changed in glance:
status: In Progress → Fix Committed
Jay Pipes (jaypipes)
Changed in glance:
status: Fix Committed → Fix Released
Jay Pipes (jaypipes)
security vulnerability: yes → no
visibility: private → public
Thierry Carrez (ttx)
security vulnerability: no → yes
Thierry Carrez (ttx)
Changed in glance:
milestone: essex-1 → 2012.1
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.