[
https://jira.nuxeo.com/browse/NXP-7324?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Mathieu Guillaume reopened NXP-7324:
------------------------------------
The status servlet should not be enabled with a common default key.
It should either have no default (in which case the servlet shouldn't answer if
not set) or there should be a server.status.enable key which defaults to false.
> Secure access to Status servlet
> -------------------------------
>
> Key: NXP-7324
> URL: https://jira.nuxeo.com/browse/NXP-7324
> Project: Nuxeo Enterprise Platform
> Issue Type: Improvement
> Components: Installers / Admin tools
> Affects Versions: 5.4.3-SNAPSHOT
> Reporter: Julien Carsique
> Assignee: Julien Carsique
> Priority: Critical
> Fix For: 5.4.3
>
>
> Server up/down is a public information but list and status of loaded
> components must be restricted to the administrators.
--
This message is automatically generated by JIRA.
For more information on JIRA, see: http://www.atlassian.com/software/jira
_______________________________________________
ECM-tickets mailing list
[email protected]
http://lists.nuxeo.com/mailman/listinfo/ecm-tickets