Murano has too open dirs (o+w)

Bug #1284574 reported by Roman Vyalov
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Fuel for OpenStack
Fix Released
High
Igor Yozhikov

Bug Description

murano-dashboard.spec

Please change directory access 777 and 766 to rights 755

Revision history for this message
Roman Vyalov (r0mikiam) wrote :

it is security fix!

Changed in fuel:
importance: Undecided → High
Revision history for this message
Mike Scherbakov (mihgen) wrote :

Both CentOS & Ubuntu are affected. Please change 766 and 777 to more secure rights (755?), or explain why we need 766/777.

Changed in fuel:
milestone: 5.0 → 4.1
status: New → Confirmed
tags: added: security
summary: - refactoring murano spec
+ Murano has too open dirs (o+w)
Revision history for this message
Dmitry Ilyin (idv1985) wrote :

It's hard to move modify config to Puppet because if my memory serves me right the config is Python code and it's not that easy to manage it woth Puppet. Well... template will do the job.

These directories are being made by the packege scripts and there permissions are set there too. Modify package scripts to get correct permissions.

Revision history for this message
Roman Vyalov (r0mikiam) wrote :

move permissions and create dir to spec, and move other to puppet ?

Revision history for this message
Timur Nurlygayanov (tnurlygayanov) wrote :

I suggest to remove modify-horizon-config.sh from Puppet to DEB/RPN packages.

Roman Vyalov (r0mikiam)
description: updated
Revision history for this message
Igor Yozhikov (iyozhikov) wrote :
Roman Vyalov (r0mikiam)
Changed in fuel:
status: Confirmed → Fix Committed
Changed in fuel:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.