OpenStack Security in openstack-security-advisories

Bug #1865086 reported by 85ufukkara85
14
This bug affects 1 person
Affects Status Importance Assigned to Milestone
openstack-org
Fix Released
Undecided
Jimmy McArthur

Bug Description

Contact
--------------
mail: <email address hidden>
mail: <email address hidden>
--------------
En;
report explanation

Since encryption and passwords are very simple on your site, the administrator knows full access to the panel and provides comments, deletions, adding pages, adding text and logging in to administrator authorized accounts.

hacking trial

https://archive.is/hfvih 27 Feb 2020 20:21:08 UTC

please review your security passwords

If the question is confirmed clearly, can I get a reward?

---------------
Tr;
Rapor açıklaması

sitenizde şifrelemeler ve şifreler çok basit olduğu için admin panele tam erişim sağlana biliyor ve bu şekilde yorum ekleme silme sayfa ekleme yazı ekleme gibi şeyler yapıla biliyor kısaca admin yetkili hesaplarına girilip işlem yapıla biliyor

hack denemesi

https://archive.is/hfvih 27 Feb 2020 20:21:08 UTC

lütfen güvenlik şifrelerinizi inceleyin

Açık doğrularırsa ödül alabilirmiyim

Revision history for this message
85ufukkara85 (85ufukkara85) wrote :
Jeremy Stanley (fungi)
affects: ossa → openstack-org
Revision history for this message
Jimmy McArthur (jimmy-l) wrote :

Hi - I appreciate the bug report. We're looking into the issue and will take the appropriate security response. We are a non-profit and as such, we don't offer bug bounties. Again though, thank you for alerting us to the issue.

Changed in openstack-org:
status: New → Confirmed
information type: Private Security → Public
Revision history for this message
Jimmy McArthur (jimmy-l) wrote :

We have secured the admin user for WP and also done a sweep of additional users to generate new passwords.

Changed in openstack-org:
assignee: nobody → Jimmy McArthur (jimmy-l)
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Duplicates of this bug

Other bug subscribers

Bug attachments

Remote bug watches

Bug watches keep track of this bug in other bug trackers.