Details
-
Bug
-
Status: Resolved
-
Critical
-
Resolution: Fixed
-
trunk, 2.7.4
Description
GET /resources gives back the directory content of /var/lib/ambari-server/resources. The directory doesn't contain any sensitive information, only files which are already visible on github. But it might freak out security guys therefore it's best to disable the listing.
Attachments
Issue Links
- is related to
-
AMBARI-25252 Disable directory Indexing at /resources
- Resolved
- links to