Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fixes #36760 - Limit access to server.xml #242

Merged
merged 1 commit into from Oct 5, 2023

Conversation

ekohl
Copy link
Member

@ekohl ekohl commented Oct 4, 2023

Prior to this the file was world readable, even though it contained passwords for the keystore. That keystore was limited to just the correct group, so it's not directly exploitable but these kind of things might be used in more complex attacks.

Fixes: 832bafa ("Initial commit of Candlepin module from the original katello-installer.")

Prior to this the file was world readable, even though it contained
passwords for the keystore. That keystore was limited to just the
correct group, so it's not directly exploitable but these kind of things
might be used in more complex attacks.

Fixes: 832bafa ("Initial commit of Candlepin module from the original katello-installer.")
@ekohl ekohl merged commit 0f0595d into theforeman:master Oct 5, 2023
5 checks passed
@ekohl ekohl deleted the 36760-server-xml-permissions branch October 5, 2023 13:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants