-
Notifications
You must be signed in to change notification settings - Fork 7.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
canal默认admin.passwd风险说明及解决方案 #4941
Milestone
Comments
鼎力支持,加强系统安全。1.1.8希望能兼容8.0.33的binlog,大佬帮忙看看,单独发了issues:#4940 |
agapple
added a commit
that referenced
this issue
Nov 8, 2023
agapple
added a commit
that referenced
this issue
Dec 29, 2023
zoemak
pushed a commit
to zoemak/canal
that referenced
this issue
Jan 30, 2024
zoemak
pushed a commit
to zoemak/canal
that referenced
this issue
Jan 30, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
近期canal社区收到关于canal admin鉴权功能通过adminPassword默认值进行撞击,绕过身份验证安全漏洞的问题。
考虑默认的安全风险,计划v1.1.8版本做如下变更:
新版本移除自带的password默认值,并在password未传入或非法时阻止节点启动来提醒用户设置自定义password
The text was updated successfully, but these errors were encountered: