Closed
Bug 729445
(wh-8282836)
Opened 14 years ago
Closed 14 years ago
addons.mo allows server directory listings
Categories
(Cloud Services :: Operations: Marketplace, task)
Cloud Services
Operations: Marketplace
Tracking
(Not tracked)
VERIFIED
FIXED
People
(Reporter: mgoodwin, Assigned: oremj)
References
()
Details
(Whiteboard: [wh-8282836][infrasec:config][ws:moderate])
Issue:
AMO allows directory listings on, for example, https://addons.mozilla.org/icons/
This issue also affects other environments (e.g. https://addons-dev.allizom.org/icons/)
Steps to Reproduce:
1) Visit https://addons.mozilla.org/icons/
2) Observe directory listing
Remediation:
Configure the server not to allow directory listings.
Comment 1•14 years ago
|
||
I think thats the default apache/redhat icons dir.
Assignee: nobody → server-ops
Group: client-services-security
Component: Public Pages → Server Operations: AMO Operations
Product: addons.mozilla.org → mozilla.org
QA Contact: web-ui → oremj
Version: unspecified → other
| Assignee | ||
Updated•14 years ago
|
Assignee: server-ops → oremj
| Assignee | ||
Comment 2•14 years ago
|
||
Fixed.
Status: NEW → RESOLVED
Closed: 14 years ago
Resolution: --- → FIXED
Updated•14 years ago
|
Status: RESOLVED → VERIFIED
Updated•11 years ago
|
Component: Server Operations: AMO Operations → Operations: Marketplace
Product: mozilla.org → Mozilla Services
You need to log in
before you can comment on or make changes to this bug.
Description
•