Enforce secured call to the server in maint job triggering
Previously, acngtool attempted to make HTTP request to an IP of the server which it picked from the configuration (or localhost) without checking who exactly was listening. This allowing an attacker to impersonate as acng server, binding the non-priviledged port in certain circumstances, and to extract the unprotected credentials (AdminAuth option). This tackles the public security vulnerability CVE-2020-5202.
Loading
Please register or sign in to comment