Uploaded image for project: 'Traffic Server'
  1. Traffic Server
  2. TS-352

Do not allow to run as root user unless explicitly compiled

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 2.1.1
    • 2.1.1
    • Configuration
    • None

    Description

      Currently one can specify the proxy.config.admin.user_id=root making the trafficserver to serve all pages under root account.
      Check the user_id provided making sure it's uid isn't zero.
      Specifying -DBIG_SECURITY_HOLE at build time overrides that check.

      Attachments

        Activity

          People

            mturk@apache.org Mladen Turk
            mturk@apache.org Mladen Turk
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: