Skip to content

xCAT Apache configuration prone to security leaks #7450

@conxuro

Description

@conxuro

xCAT Apache configuration sets explicitly option Indexes and Require all granted to the whole /install directory. Both options can result in accessing to the custom config files (e.g. /install/custom as the documentation usually refers), and also to other files.

A more critical security issue is if full backups (with passwords and hosts) are made inside /install (like it is in a document example from https://xcat-docs.readthedocs.io/en/stable/guides/admin-guides/references/man1/dumpxCATdb.1.html)

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions