1
0
Fork 0
mirror of https://github.com/pikvm/pikvm.git synced 2026-03-02 18:16:56 -05:00

Exposed Apache htpasswd file #2

Closed
opened 2026-02-20 13:18:27 -05:00 by deekerman · 3 comments
Owner

Originally created by @r0x0d on GitHub (Sep 27, 2019).

Originally assigned to: @mdevaev on GitHub.

Potential security breach. See /configs/kvmd/htpasswd

Originally created by @r0x0d on GitHub (Sep 27, 2019). Originally assigned to: @mdevaev on GitHub. Potential security breach. See /configs/kvmd/htpasswd
Author
Owner

@mdevaev commented on GitHub (Sep 27, 2019):

It has limited permissions (600) and readable only by root and kvmd group. What exactly is the problem?

@mdevaev commented on GitHub (Sep 27, 2019): It has limited permissions (600) and readable only by root and kvmd group. What exactly is the problem?
Author
Owner

@r0x0d commented on GitHub (Sep 28, 2019):

I saw the creds in the htpasswd file and thought it was a mistake publishing it on a open source repo, usually this kinda of stuff is inside a environment variable to not be exposed to public.

I wanted to report it before anyone else would abuse of this breach.

If your project has a different structure and this indeed needed to be publish, then it's ok.

@r0x0d commented on GitHub (Sep 28, 2019): I saw the creds in the htpasswd file and thought it was a mistake publishing it on a open source repo, usually this kinda of stuff is inside a environment variable to not be exposed to public. I wanted to report it before anyone else would abuse of this breach. If your project has a different structure and this indeed needed to be publish, then it's ok.
Author
Owner

@mdevaev commented on GitHub (Sep 28, 2019):

Ah, I get it. Thank you for your concern! Everything is fine. This file contains default settings that change during installation.

@mdevaev commented on GitHub (Sep 28, 2019): Ah, I get it. Thank you for your concern! Everything is fine. This file contains default settings that change during installation.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/pikvm-pikvm#2
No description provided.