Uploaded image for project: 'Application Server 7'
  1. Application Server 7
  2. AS7-5577

CLONE - Disable JGroups diagnostics service by default

    XMLWordPrintable

Details

    Description

      The JGroups diagnostics service should be disabled by default.

      This can be accomlished by removing the "diagnostics-socket-binding" attribute from the <transport> tags in the JGroups subsystem.

      This is a security issue, because the diagnostics port enables many security-sensitive operations, with no authentication, including:

      • full thread dump of the JVM
      • add/remove JGroups protocols
      • call any method on any JGroups protocol, passing in arbitrary arguments

      Attachments

        Activity

          People

            rhn-engineering-rhusar Radoslav Husar
            rhn-support-dereed Dennis Reed
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: