View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
17580 | Bug reports | Security | public | 2021-09-08 13:02 | 2024-09-12 16:47 |
Reporter | Mazi | Assigned To | galads | ||
Priority | none | Severity | minor | ||
Status | confirmed | Resolution | open | ||
Product Version | 3.25.20 | ||||
Summary | 17580: readme and release note are publicly accessible and can reveal version details to attackers | ||||
Description | The readme and for some systems the release note details can be accessed publicly (example: https://ls3.my-survey.host/README.md or https://demo.limesurvey.org/docs/release_notes.txt). This could reveal version details to attackers. Should we extend the .htaccess file to not make these accessible from the web? | ||||
Tags | No tags attached. | ||||
Bug heat | 260 | ||||
Complete LimeSurvey version number (& build) | 3.22.10+200323 | ||||
I will donate to the project if issue is resolved | No | ||||
Browser | Chrome | ||||
Database type & version | MySQL | ||||
Server OS (if known) | Ubuntu 20 | ||||
Webserver software & version (if known) | Apache | ||||
PHP Version | 7.2.24 | ||||
It's false for docs/* (with apache) Must be added in nginx part for manual https://manual.limesurvey.org/General_FAQ#With_nginx_webserver |
|
I think you can figure out the major version by just looking at the login and code, so I am not so worried about the README, but I agree that the changelog should be either renamed (maybe *.php with a die()) or removed. |
|
@c_schmitz : maybe we can remove docs/* from zip file via .gitattributes ? Else for apache : doc reading is disable Need a IIS … |
|
Date Modified | Username | Field | Change |
---|---|---|---|
2021-09-08 13:02 | Mazi | New Issue | |
2021-09-08 14:58 | DenisChenu | Note Added: 66404 | |
2021-09-08 14:58 | DenisChenu | Bug heat | 250 => 252 |
2021-09-09 08:32 | c_schmitz | Note Added: 66411 | |
2021-09-09 08:32 | c_schmitz | Bug heat | 252 => 254 |
2021-09-09 08:32 | guest | Bug heat | 254 => 260 |
2021-09-09 08:36 | galads | Assigned To | => galads |
2021-09-09 08:36 | galads | Status | new => confirmed |
2024-09-12 16:47 | DenisChenu | Note Added: 81005 |