[Openstack-security] [Bug 1506419] Re: Running Flask server in debug mode may be a security issue

Jeremy Stanley fungi at yuggoth.org
Tue Oct 20 22:52:49 UTC 2015


Added a "won't fix" security advisory task for this and marked it as a
hardening opportunity (class D in https://security.openstack.org/vmt-
process.html#incident-report-taxonomy ) due to being an sensitive
information disclosure occurring only in DEBUG level logs.

** Also affects: ossa
   Importance: Undecided
       Status: New

** Changed in: ossa
       Status: New => Won't Fix

** Tags added: security

-- 
You received this bug notification because you are a member of OpenStack
Security, which is subscribed to OpenStack.
https://bugs.launchpad.net/bugs/1506419

Title:
  Running Flask server in debug mode may be a security issue

Status in Ironic Inspector:
  Fix Committed
Status in Ironic Inspector liberty series:
  Fix Committed
Status in Ironic Inspector mitaka series:
  Fix Committed
Status in OpenStack Security Advisory:
  Won't Fix

Bug description:
  A lot of people default to running their servers in debug mode. While
  handy for getting the full logs, in our case it will also allow access
  to Flask console, which may pose a security risk. We need a separate
  option for this.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ironic-inspector/+bug/1506419/+subscriptions




More information about the Openstack-security mailing list