Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-121680

Apache httpd /icons directory should not be indexed

Linking RHIVOS CVEs to...Migration: Automation ...RHELPRIO AssignedTeam ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • rhel-8.10, rhel-9.6, rhel-10.0
    • httpd
    • None
    • None
    • Low
    • rhel-stacks-web-servers
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      What were you trying to do that didn't work?

      Security scanners report that /icons is indexed/listable.

      What is the impact of this issue to you?

      Qualys and other scanners report this as a potential vulnerability.

      Please provide the package NVR for which the bug is seen:

      httpd (all versions)

      How reproducible is this bug?:

      Always

      Steps to reproduce

      1. Install httpd
      2. curl 127.0.0.1/icons/

      Expected results

      403 Forbidden

      Actual results

      Lists contents of directory

      Additional Information

      This is the default configuration from upstream Apache httpd, which has the following in httpd/docs/conf/extra/httpd-autoindex.conf.in (which eventually generates the autoindex.conf we provide):

      <Directory "@exp_iconsdir@">
          Options Indexes MultiViews
          AllowOverride None
          Require all granted
      </Directory>

       

      Changing this to the following (removing Indexes option) would fix the issue:

      <Directory "@exp_iconsdir@">
          Options MultiViews
          AllowOverride None
          Require all granted
      </Directory>

      Note that we already modify this file to add "FollowSymlinks" by default, which upstream does not.

              luhliari@redhat.com Lubos Uhliarik
              tsorense@redhat.com Thomas Sorensen
              Lubos Uhliarik Lubos Uhliarik
              Branislav Náter Branislav Náter
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated: