[Bug 858867] Re: XMLRPC allows unauthed users access to various methods (which it shouldn't)

2013-08-29 Thread Timo Aaltonen
marking wontfix as per discussion ** Changed in: cobbler (Ubuntu) Status: Triaged = Won't Fix ** Changed in: cobbler (Ubuntu) Milestone: quantal-alpha-3 = None -- You received this bug notification because you are a member of Ubuntu Server Team, which is a bug assignee.

[Bug 858867] Re: XMLRPC allows unauthed users access to various methods (which it shouldn't)

2012-08-23 Thread girts
Will it be fixed in Ubuntu 12.04 release because it is important security issue?? It is security issue!! -- You received this bug notification because you are a member of Ubuntu Server Team, which is a bug assignee. https://bugs.launchpad.net/bugs/858867 Title: XMLRPC allows unauthed users

[Bug 858867] Re: XMLRPC allows unauthed users access to various methods (which it shouldn't)

2012-08-23 Thread Dave Walker
This is not an issue that will be closed as described, as many do not feel that it is something that worthy of significant work. We would be happy to sponsor a patch, which exposes this as an option to disable.. but it's not something that will be driven by those currently involved. I am sorry if

[Bug 858867] Re: XMLRPC allows unauthed users access to various methods (which it shouldn't)

2012-08-07 Thread James Page
** Changed in: cobbler (Ubuntu Quantal) Status: Triaged = Won't Fix -- You received this bug notification because you are a member of Ubuntu Server Team, which is a bug assignee. https://bugs.launchpad.net/bugs/858867 Title: XMLRPC allows unauthed users access to various methods

[Bug 858867] Re: XMLRPC allows unauthed users access to various methods (which it shouldn't)

2012-08-07 Thread Launchpad Bug Tracker
This bug was fixed in the package cobbler - 2.2.2-0ubuntu36 --- cobbler (2.2.2-0ubuntu36) quantal; urgency=low * debian/README.Debian: Add Warning note mentioning that XMLRPC API allows unauthenticated access to certain API methods. (LP: #858867) -- Andres Rodriguez

[Bug 858867] Re: XMLRPC allows unauthed users access to various methods (which it shouldn't)

2012-08-07 Thread Launchpad Bug Tracker
** Branch linked: lp:ubuntu/cobbler -- You received this bug notification because you are a member of Ubuntu Server Team, which is a bug assignee. https://bugs.launchpad.net/bugs/858867 Title: XMLRPC allows unauthed users access to various methods (which it shouldn't) To manage

[Bug 858867] Re: XMLRPC allows unauthed users access to various methods (which it shouldn't)

2012-07-24 Thread James Page
Notes from todays IRC meeting: Launchpad bug 858867 in cobbler (Ubuntu Quantal) XMLRPC allows unauthed users access to various methods (which it shouldn't) [Medium,Triaged] https://launchpad.net/bugs/858867 jamespage o/ I second smoser's opinion on this bug its never going to be fixed - so

[Bug 858867] Re: XMLRPC allows unauthed users access to various methods (which it shouldn't)

2012-07-17 Thread Andres Rodriguez
** Changed in: cobbler (Ubuntu Quantal) Assignee: Ubuntu Server Team (ubuntu-server) = Andres Rodriguez (andreserl) -- You received this bug notification because you are a member of Ubuntu Server Team, which is a bug assignee. https://bugs.launchpad.net/bugs/858867 Title: XMLRPC allows

[Bug 858867] Re: XMLRPC allows unauthed users access to various methods (which it shouldn't)

2012-07-17 Thread James Cammarata
In my opinion as the maintainer, this is not a bug and will not be fixed upstream. Any functions that modify data require a login, and certain functions (like those performed by koan) require access to the XMLRPC endpoint without a login or access to the token stored locally for the CLI. At no

[Bug 858867] Re: XMLRPC allows unauthed users access to various methods (which it shouldn't)

2012-07-17 Thread Scott Moser
Given James' and Daviey's comments above, I think we should just let this be. Its more likely that sensitive information would live in the kickstart files (url=) which are not protected at all either. Is there some appropriate way to document this and close it as such? -- You received this bug

[Bug 858867] Re: XMLRPC allows unauthed users access to various methods (which it shouldn't)

2012-07-12 Thread Stéphane Graber
Daviey: Can we get a status update on this one? are you guys still planning on having it fixed for the point release? ** Changed in: cobbler (Ubuntu Quantal) Status: Confirmed = Triaged ** Changed in: cobbler (Ubuntu Precise) Status: Confirmed = Triaged ** Changed in: cobbler

[Bug 858867] Re: XMLRPC allows unauthed users access to various methods (which it shouldn't)

2012-06-28 Thread Kate Stewart
** Also affects: cobbler (Ubuntu Quantal) Importance: Medium Assignee: Ubuntu Server Team (ubuntu-server) Status: Confirmed ** Changed in: cobbler (Ubuntu Quantal) Milestone: quantal-alpha-2 = quantal-alpha-3 -- You received this bug notification because you are a member of

[Bug 858867] Re: XMLRPC allows unauthed users access to various methods (which it shouldn't)

2012-06-07 Thread Stéphane Graber
** Changed in: cobbler (Ubuntu) Milestone: quantal-alpha-1 = quantal-alpha-2 -- You received this bug notification because you are a member of Ubuntu Server Team, which is a bug assignee. https://bugs.launchpad.net/bugs/858867 Title: XMLRPC allows unauthed users access to various methods

[Bug 858867] Re: XMLRPC allows unauthed users access to various methods (which it shouldn't)

2012-05-31 Thread James Page
** Changed in: cobbler (Ubuntu Precise) Milestone: ubuntu-12.04 = ubuntu-12.04.1 ** Changed in: cobbler (Ubuntu) Milestone: ubuntu-12.04 = quantal-alpha-1 -- You received this bug notification because you are a member of Ubuntu Server Team, which is a bug assignee.

[Bug 858867] Re: XMLRPC allows unauthed users access to various methods (which it shouldn't)

2012-03-26 Thread Martin Pitt
** Changed in: cobbler (Ubuntu Precise) Milestone: ubuntu-12.04-beta-2 = ubuntu-12.04 -- You received this bug notification because you are a member of Ubuntu Server Team, which is a bug assignee. https://bugs.launchpad.net/bugs/858867 Title: XMLRPC allows unauthed users access to

[Bug 858867] Re: XMLRPC allows unauthed users access to various methods (which it shouldn't)

2012-03-01 Thread Martin Pitt
** Changed in: cobbler (Ubuntu) Milestone: ubuntu-12.04-beta-1 = ubuntu-12.04-beta-2 -- You received this bug notification because you are a member of Ubuntu Server Team, which is a bug assignee. https://bugs.launchpad.net/bugs/858867 Title: XMLRPC allows unauthed users access to various

[Bug 858867] Re: XMLRPC allows unauthed users access to various methods (which it shouldn't)

2012-02-05 Thread Martin Pitt
** Changed in: cobbler (Ubuntu) Milestone: precise-alpha-2 = ubuntu-12.04-beta-1 -- You received this bug notification because you are a member of Ubuntu Server Team, which is a bug assignee. https://bugs.launchpad.net/bugs/858867 Title: XMLRPC allows unauthed users access to various

[Bug 858867] Re: XMLRPC allows unauthed users access to various methods (which it shouldn't)

2011-12-01 Thread Kate Stewart
updating milestone, since wasn't release as part of alpha-1 ** Changed in: cobbler (Ubuntu Precise) Milestone: precise-alpha-1 = precise-alpha-2 ** Tags added: rls-mgr-p-trackign ** Tags removed: rls-mgr-p-trackign ** Tags added: rls-mgr-p-tracking -- You received this bug notification

[Bug 858867] Re: XMLRPC allows unauthed users access to various methods (which it shouldn't)

2011-10-16 Thread Dave Walker
** Changed in: cobbler (Ubuntu Oneiric) Assignee: (unassigned) = Ubuntu Server Team (ubuntu-server) ** Changed in: cobbler (Ubuntu Precise) Assignee: (unassigned) = Ubuntu Server Team (ubuntu-server) -- You received this bug notification because you are a member of Ubuntu Server Team,

[Bug 858867] Re: XMLRPC allows unauthed users access to various methods (which it shouldn't)

2011-10-10 Thread daveb
Right - well the impact / if this is even a security bug is going to be up to the user. Personally, I don't see why the methods are exposed without good reason - is it a requirement that they are exposed? -- You received this bug notification because you are a member of Ubuntu Server Team, which

[Bug 858867] Re: XMLRPC allows unauthed users access to various methods (which it shouldn't)

2011-10-09 Thread Dave Walker
Confirmed, with the following. Marking medium, and tagging as a security bug. I'm not certain it exposes credentials, or anything else highly privileged. If this is not the case, please update the bug with an example. Thanks. #!/usr/bin/python import xmlrpclib server =

[Bug 858867] Re: XMLRPC allows unauthed users access to various methods (which it shouldn't)

2011-09-28 Thread daveb
** Visibility changed to: Public -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to cobbler in Ubuntu. https://bugs.launchpad.net/bugs/858867 Title: XMLRPC allows unauthed users access to various methods (which it shouldn't) To

[Bug 858867] Re: XMLRPC allows unauthed users access to various methods (which it shouldn't)

2011-09-28 Thread Serge Hallyn
** Changed in: cobbler (Ubuntu) Importance: Undecided = High -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to cobbler in Ubuntu. https://bugs.launchpad.net/bugs/858867 Title: XMLRPC allows unauthed users access to various methods