Ticket #59 (new bugs)
root directory exposed through srm (#2550)
| Reported by: | patrick | Owned by: | litvinse |
|---|---|---|---|
| Priority: | major | Milestone: | 1.8.0-16 |
| Component: | srm | Keywords: | |
| Cc: | Sub Version: |
Description
Through my srm client (which calls srmLs) I am able to list the root directory of the srm host:
[cameron@hyper] cli> ./ngls srm://srm.ndgf.org var boot tmp etc media cdrom lib ...
Although I cannot list any of these directories except pnfs, I think this is a potential security risk. Interestingly, when I use the fullDetailedListing option, it behaves as it should and I only see the pnfs directory. I don't think it is a configuration issue, I see this at all T1 dcache sites, eg
Change History
comment:1 Changed 4 years ago by patrick
- Owner changed from patrick to omsynge
- Milestone changed from 1.8.0-12-patch7 to 1.8.0-13
comment:3 Changed 4 years ago by patrick
- Owner changed from litvinse to patrick
- Status changed from new to assigned
Note: See
TracTickets for help on using
tickets.
