Project

General

Profile

Actions

Architecture #15109

open

Rudder should not have exec binaries in /var, it conflicts with security best practices

Added by François ARMAND almost 5 years ago. Updated over 2 years ago.

Status:
New
Priority:
N/A
Assignee:
-
Category:
Security
Target version:
-
Effort required:
Medium
Name check:
Fix check:
Regression:

Description

In Rudder, we have executable binaries in /var/rudder/cfengine-community/bin/ (like cf-agent etc).

This conflict with security best practice, particlarly mounting /var in noexec.

Moreover, binaries in /var/rudder/cfengine-community/bin/ are duplicated and they are also in /opt/rudder/bin/

Actions

Also available in: Atom PDF