Uploaded image for project: 'Application Server 7'
  1. Application Server 7
  2. AS7-5577

CLONE - Disable JGroups diagnostics service by default

XMLWordPrintable

      The JGroups diagnostics service should be disabled by default.

      This can be accomlished by removing the "diagnostics-socket-binding" attribute from the <transport> tags in the JGroups subsystem.

      This is a security issue, because the diagnostics port enables many security-sensitive operations, with no authentication, including:

      • full thread dump of the JVM
      • add/remove JGroups protocols
      • call any method on any JGroups protocol, passing in arbitrary arguments

              rhn-engineering-rhusar Radoslav Husar
              rhn-support-dereed Dennis Reed
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: