Skip to content
This repository has been archived by the owner on Sep 23, 2020. It is now read-only.

pass through cp propagation needs a path whitelist #69

Open
buzztroll opened this issue Jul 22, 2011 · 1 comment
Open

pass through cp propagation needs a path whitelist #69

buzztroll opened this issue Jul 22, 2011 · 1 comment

Comments

@buzztroll
Copy link
Contributor

A side effect of adding copy propagation for cumulus urls is that it can also be used as a pass through propagation method. This is off by default, but when enabled it has bad security implications. The nimbus user will be copying the images, which means that any file in the cumulus archive could be copied for boot. We need to have a whitelist of directories and some documentation heavily warning users about the implications if they enable pass through cp propagation.

@buzztroll
Copy link
Contributor Author

It should further be noted that a user can attempt to boot any file to which the nimbus user on the VMM has read access.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant