Details
-
Bug
-
Resolution: Fixed
-
Critical
-
None
-
None
-
3
-
9223372036854775807
Description
Non-root users have the ability to read changelog entries (which contain filenames and FIDs). More importantly, non-root users have the ability to clear changelogs regardless of permissions on the mountpoint.
This has potential security implications, in that non-privileged users gain the ability to see information in directories to which they shouldn't have access, and there is also potential for deliberate or accidental DOS by clearing changelogs before the intended reader gets to them (e.g. Robinhood, etc.)
Attachments
Issue Links
- mentioned in
-
Page Loading...