openstack-helm/horizon/templates/bin
Dmitrii Kabanov b8eb8b3581 Horizon: HTTP Verb Tampering vulnerability fix
The patch fixes the HTTP verb tampering issue. The idea is to disable
unnecessary HTTP methods for the Horizon. You can find a link to
the description [0] and a link to the White Paper [1] below:

CAPEC-274: HTTP Verb Tampering
[0] https://capec.mitre.org/data/definitions/274.html

Bypassing Web Authentication and Authorization with HTTP Verb Tampering
(Bypassing_VBAAC_with_HTTP_Verb_Tampering.pdf)
[1] https://dl.packetstormsecurity.net/papers/web/Bypassing_VBAAC_with_HTTP_Verb_Tampering.pdf

Change-Id: I98169973410bc1dce779ac1e870256b9a45d2cc8
2018-09-28 12:12:41 -07:00
..
_db-sync.sh.tpl Revert "Update OSH Author copyrights to OSF" 2018-08-28 17:25:13 +00:00
_django.wsgi.tpl Horizon: add policy override and make chart image agnostic 2017-08-29 21:59:05 +00:00
_horizon.sh.tpl Horizon: HTTP Verb Tampering vulnerability fix 2018-09-28 12:12:41 -07:00
_manage.py.tpl Horizon: add policy override and make chart image agnostic 2017-08-29 21:59:05 +00:00