Bug ID | 955801 |
---|---|
Summary | libzypp sends X-ZYpp-AnonymousId to third party mirrors and repositories |
Classification | openSUSE |
Product | openSUSE Distribution |
Version | Leap 42.1 |
Hardware | Other |
OS | Other |
Status | NEW |
Severity | Normal |
Priority | P5 - None |
Component | libzypp |
Assignee | zypp-maintainers@forge.provo.novell.com |
Reporter | astieger@suse.com |
QA Contact | qa-bugs@suse.de |
Found By | Security Response Team |
Blocker | --- |
/var/lib/zypp/AnonymousId contains a per-installation unique identifier which is sent as the X-ZYpp-AnonymousId header (boo#431571) This header is sent to hosts other than download.opensuse.org following a 301 redirect from mirrorbrain. As mirror hosts have no use and no business for this information, it must not be sent there.