Skip to content
Commit 3b91874b authored by Eduard Bloch's avatar Eduard Bloch
Browse files

Enforce secured call to the server in maint job triggering

Previously, acngtool attempted to make HTTP request to an IP of the
server which it picked from the configuration (or localhost) without
checking who exactly was listening. This allowing an attacker to
impersonate as acng server, binding the non-priviledged port in certain
circumstances, and to extract the unprotected credentials (AdminAuth
option).

This tackles the public security vulnerability CVE-2020-5202.
parent 7ebe8270
Loading
Loading
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment