Skip to content

Address for possible removed rules on child vdirs#1290

Merged
dpaulson45 merged 1 commit into
mainfrom
dpaul-CveUpdate
Oct 12, 2022
Merged

Address for possible removed rules on child vdirs#1290
dpaulson45 merged 1 commit into
mainfrom
dpaul-CveUpdate

Conversation

@dpaulson45
Copy link
Copy Markdown
Member

Issue:
If someone goes and modifies or removes all mitigation rules on child vdir, then the server is not secure from the mitigation. We should flag that as an issue then.

Fix:
Create a list of all rules on Default Web Site configuration file that met the criteria for the mitigation and if all those rules are removed on child vdirs, flag this as a security issue.

Validation:
Lab tested

@dpaulson45 dpaulson45 requested a review from a team as a code owner October 12, 2022 18:43
@dpaulson45 dpaulson45 merged commit 0b2189f into main Oct 12, 2022
@dpaulson45 dpaulson45 deleted the dpaul-CveUpdate branch October 12, 2022 19:00
@dpaulson45 dpaulson45 added Enhancement New feature or request Health Checker labels Oct 21, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Enhancement New feature or request Health Checker

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants