Uploaded image for project: 'MariaDB MaxScale'
  1. MariaDB MaxScale
  2. MXS-5610

Exposure of Internal Files in MaxScale Download Directory

    XMLWordPrintable

Details

    • Bug
    • Status: Closed (View Workflow)
    • Major
    • Resolution: Fixed
    • 25.01.2
    • N/A
    • build
    • None

    Description

      The security team noticed that the build.properties and build.log (86) files are accessible in the download directory. These files appear to expose internal build infrastructure details as well as employee email addresses.

      Example:
      https://dlm.mariadb.com/browse/mariadb_maxscale_enterprise/25.01.2/?flat=1

      In this flat view you will see:

      • build.log files containing internal information
      • build.properties file that exposes:

      These details do not seem necessary for customer facing downloads. This differs from what is published under the Enterprise builds where we do not publish build.log or build.properties.

      Could you investigate why these files are being exposed and confirm whether they can be removed from public access?

      Attachments

        Activity

          People

            tturenko Timofey Turenko
            mdeweerd Michael Deweerd
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Git Integration

                Error rendering 'com.xiplink.jira.git.jira_git_plugin:git-issue-webpanel'. Please contact your Jira administrators.