Details
-
Improvement
-
Status: Closed
-
Major
-
Resolution: Fixed
-
None
-
None
-
None
Description
The lucene policy is strict and specifies only specific locations.
Unfortunately currently the solr policy allows read to ALL FILES
The tests shouldn't be able to read anywhere, e.g. my .ssh/ directory or whatever.
It is a necessary painful step to eventually eliminate directory traversal attacks, etc.
Attachments
Attachments
Issue Links
- relates to
-
SOLR-14020 move hadoop hacks out of lucene TestSecurityManager into a solr one
- Closed