Details
-
Task
-
Status: Resolved
-
Major
-
Resolution: Fixed
-
2.6.0
Description
GET /resources gives back the directory content of /var/lib/ambari-server/resources. The directory doesn't contain any sensitive information, only files which are already visible on github. But it might freak out security guys therefore it's best to disable the listing.
Attachments
Issue Links
- relates to
-
AMBARI-25390 Ambari is indexing all subdirectories contents under /resources folder via API.
- Resolved
- links to