Skip to content

Disable CXF Services Listing#268

Merged
ilgrosso merged 1 commit intoapache:2_1_Xfrom
coheigea:services-listing
May 27, 2021
Merged

Disable CXF Services Listing#268
ilgrosso merged 1 commit intoapache:2_1_Xfrom
coheigea:services-listing

Conversation

@coheigea
Copy link
Copy Markdown
Contributor

As Syncope 2.1.x is stuck on CXF 3.2.x, it is vulnerable to:

http://cxf.apache.org/security-advisories.data/CVE-2020-13954.txt.asc

I confirmed with this PR you can no longer see the services page (http://localhost:9080/syncope/rest/services)

@ilgrosso
Copy link
Copy Markdown
Member

@coheigea when you disable service listing, does doc page still works, a.k.a. /syncope/ which output is similar to http://syncope.apache.org/rest/2.1/index.html ?

@coheigea
Copy link
Copy Markdown
Contributor Author

Yes, it does, as does the WADL, openapi + Swagger links.

@ilgrosso ilgrosso merged commit ff601ba into apache:2_1_X May 27, 2021
@coheigea coheigea deleted the services-listing branch May 27, 2021 06:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants