Uploaded image for project: 'Satellite'
  1. Satellite
  2. SAT-26837

On capsules, a user can read the directory cgi-bin of the server

XMLWordPrintable

    • 0
    • False
    • Hide

      None

      Show
      None
    • False
    • foreman-installer-3.12.0-0.2.rc1
    • 0
    • Platform
    • Moderate
    • None

      Description of problem:

      A user can read the cgi-bin directory (even if it's empty) of a capsule with a browser going to https://<capsule>/cgi-bin/

       

      How reproducible:

      Always

      Is this issue a regression from an earlier version:

       

      Steps to Reproduce:

      1. Setup a capsule 

      2. point a browser to https://<capsule>/cgi-bin/

       

      Actual behavior:
      Apache lists the content of the directory (by default empty, but it does list it)

      Expected behavior:
      Either deny directory listing or at least have a configuration option to disable Indexes

       

      Business Impact / Additional info:

      Security scanners complain about this behavior and customers have to fix it manually outside of satellite-installer (and re-apply the fix after every execution).

       

            ekohlvan@redhat.com Ewoud Kohl van Wijngaarden
            rhn-support-jpasqual Joniel Pasqualetto
            Radek Mynar Radek Mynar
            Votes:
            0 Vote for this issue
            Watchers:
            5 Start watching this issue

              Created:
              Updated:
              Resolved: