Actions
Bug #16552
closedWebdav password is ignored and access is granted for all nodes in allowed networks
Pull Request:
Severity:
UX impact:
User visibility:
Effort required:
Priority:
0
Name check:
Reviewed
Fix check:
Checked
Regression:
Description
Since apache 2.4 and changes in Require
semantic, the allowed network and authentication are now both valid, so being in the allowed networks skips auth checks.
We need to add something like:
<RequireAll> <RequireAny> Require ip 127.0.0.1 ... </RequireAny> Require valid-user
Updated by Alexis Mousset almost 5 years ago
- Status changed from New to In progress
- Assignee set to Alexis Mousset
Updated by Vincent MEMBRÉ almost 5 years ago
- Target version changed from 6.0.3 to 6.0.4
Updated by Vincent MEMBRÉ over 4 years ago
- Target version changed from 6.0.4 to 6.0.5
Updated by Alexis Mousset over 4 years ago
- Status changed from In progress to Pending release
Applied in changeset rudder|f57041c85f509d706e28abe4b666a706d6ee4032.
Updated by Alexis Mousset over 4 years ago
- Fix check changed from To do to Checked
Updated by Alexis Mousset over 4 years ago
- Name check changed from To do to Reviewed
Updated by Vincent MEMBRÉ over 4 years ago
- Status changed from Pending release to Released
This bug has been fixed in Rudder 6.0.5 which was released today.
Updated by Alexis Mousset over 4 years ago
- Category changed from Techniques to Security
Actions