Project

General

Profile

Actions

Bug #11110

closed

Check permissions on /var/rudder files, particularly modified-files

Added by Alexis Mousset over 7 years ago. Updated over 5 years ago.

Status:
Released
Priority:
N/A
Category:
System techniques
Target version:
Severity:
Critical - prevents main use of Rudder | no workaround | data loss | security
UX impact:
User visibility:
Operational - other Techniques | Technique editor | Rudder settings
Effort required:
Very Small
Priority:
0
Name check:
Fix check:
Regression:

Description

Modified files have the permission of the modified files, which can lead to be world-readable as the folder itself is 755.

For example, if I edit a 644 file in a 700 directory, it will be 644 in the modified-files, and accessible to everybody. There should be no need for modified-files to be world-readable, and we should enforce 700 for it.

Actions

Also available in: Atom PDF