-
Notifications
You must be signed in to change notification settings - Fork 1.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[CVE-2019-12105] Unauthenticated user can read log files or restart a service #1245
Comments
Supervisor requires that a configuration file be created before Our packages only provide a command, Since the
The
I do not think this should have been a CVE. The ability to run an open server will not be removed because users often use it for local development. However, an additional warning message was added to the documentation. Note: Supervisor is re-packaged for various distributions. Those packages are created by others who are not involved with the Supervisor project. Those packages may contain changes such as code modifications, init scripts, or included configuration files. We have no way to know what all the various third party packages do with regards to this issue, and only they can change their packages. |
Luan Souza ([email protected]) wrote in email:
The text was updated successfully, but these errors were encountered: