Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dashboard accessible from outside by default (since 1.7.25) #1958

Closed
silentw opened this issue Oct 26, 2021 · 3 comments
Closed

Dashboard accessible from outside by default (since 1.7.25) #1958

silentw opened this issue Oct 26, 2021 · 3 comments

Comments

@silentw
Copy link

silentw commented Oct 26, 2021

When using Dashboard version 1.7.24, the dashboard is not accessible from outside of the server (401).
As of version 1.7.25, it is accessible from outside of the server by default.

I have no authorization configured, so by default it should not allow access from outside of the server.

@silentw
Copy link
Author

silentw commented Oct 26, 2021

Possibly this #1904 has broken this functionality.

@odinserj
Copy link
Member

Oh! Thank you so much for reporting this, new property assignment broke the whole logic. I'm releasing 1.7.26 with the fix right now!

@odinserj
Copy link
Member

I've just released the fix, please see https://www.hangfire.io/blog/2021/10/27/hangfire-1.7.26.html. Security updates can be found on this page: https://www.hangfire.io/blog/security.html, you can subscribe to it via RSS (new posts available immediately) or email (sent once a day when new post is available).

In order to give the community time to respond and upgrade we strongly urge you report all security issues privately. Please email us at security@hangfire.io with details and we will respond ASAP. Security issues always take precedence over bug fixes and feature work.

Thanks again for reporting this!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Development

No branches or pull requests

2 participants