/etc/netplan/00-snapd-config.yaml should not be world readable

Bug #1634775 reported by Oliver Grawert
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Snappy
Fix Released
Critical
Unassigned
subiquity (Ubuntu)
Fix Released
Critical
Unassigned

Bug Description

apparently console-conf creates /etc/netplan/00-snapd-config.yaml world readable and puts the wireleass password in clear text in there.

Oliver Grawert (ogra)
Changed in snappy:
importance: Undecided → Critical
Changed in subiquity (Ubuntu):
importance: Undecided → Critical
Revision history for this message
Michael Hudson-Doyle (mwhudson) wrote :

Ah oops the console-conf log files are world readable and contain the netplan config...

Changed in subiquity (Ubuntu):
status: New → Fix Committed
status: Fix Committed → In Progress
Changed in subiquity (Ubuntu):
status: In Progress → Fix Committed
Changed in subiquity (Ubuntu):
status: Fix Committed → Fix Released
Michael Vogt (mvo)
Changed in snappy:
status: New → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.