Bug 45680

Summary: UCS 4.1: unprotected univention-directory-reports
Product: UCS Reporter: Florian Best <best>
Component: UMC - Domain management (Generic)Assignee: Florian Best <best>
Status: CLOSED FIXED QA Contact: Felix Botner <botner>
Severity: normal    
Priority: P5 CC: ahlers, birkefeld, botner, grandjean
Version: UCS 4.1   
Target Milestone: UCS 4.1-5   
Hardware: Other   
OS: Linux   
What kind of report is it?: Security Issue What type of bug is this?: ---
Who will be affected by this bug?: --- How will those affected feel about the bug?: ---
User Pain: Enterprise Customer affected?:
School Customer affected?: Yes ISV affected?:
Waiting Support: Flags outvoted (downgraded) after PO Review:
Ticket number: Bug group (optional): Security
Max CVSS v3 score:
Bug Depends on: 45644    
Bug Blocks:    

Comment 1 Florian Best univentionstaff 2017-11-09 14:53:47 CET
A different fix has been commited to UCS 4.1-5 which enabled the apache configuration so that the directory is access protected.

univention-management-console-module-udm (6.0.11-41)
16373646cbdd | Bug #45680: protect directory reports from unauthenticated access

changelog-4.1-5.xml
0886a1748adf | Changelog Bug #45680
Comment 2 Felix Botner univentionstaff 2017-11-10 13:35:31 CET
Not updating umc/module/udm/users/self/disabled
ERROR: Site univention-directory-manager.conf does not exist!
[ ok ] Reloading web server config: apache2.
Trigger für python-support werden verarbeitet ...

root@master:~# ls /etc/apache2/sites-available/
default  default.debian  default-ssl  default-ssl.debian  univention-directory-manager  univention-management-console  univention-saml
root@master:~# file /etc/apache2/sites-available/univention-directory-manager 
/etc/apache2/sites-available/univention-directory-manager: UTF-8 Unicode text


=> a2ensite univention-directory-manager (not univention-directory-manager.conf)
Comment 3 Florian Best univentionstaff 2017-11-10 13:45:29 CET
Oups, yes.

univention-management-console-module-udm (6.0.11-42)
3e61d0953cdd | Bug #45680: fix typo
Comment 4 Felix Botner univentionstaff 2017-11-13 12:48:02 CET
OK - univention-management-console-module-udm
     (-Indexes for univention-directory-reports)
OK - changelog
Comment 5 Erik Damrose univentionstaff 2017-11-21 15:01:11 CET
Close: UCS 4.1-5 has been released.