Skip to content

UI compromises DIN EN ISO/IEC 27001 by trying to fetch images from gravatar.com #5749

@s-seitz

Description

@s-seitz
ISSUE TYPE
  • Improvement Request
COMPONENT NAME

UI


CLOUDSTACK VERSION

4.16


CONFIGURATION

any

OS / ENVIRONMENT

any

SUMMARY

The UI tries to get a gravatar Image for each username in listUsers, which potentially compromises the audit trail of CS Installations in DIN EN ISO/IEC 27001-required environments.

STEPS TO REPRODUCE

Login into CS, and follow the requests, using the built-in Web-Developer-Tools of Firefox or Chrome.


EXPECTED RESULTS

No request to any external ressource.


ACTUAL RESULTS

The current CS UI tries to fetch an image from gravatar.com and compromises a private Infrastructure by exposing referrer and email-address of any listUser.


Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions