YunoHost-Apps / syncthing_ynh

Syncthing package for YunoHost
https://syncthing.net/
Mozilla Public License 2.0
25 stars 5 forks source link

Unprotected admin web-Interface exposed to the internet by default #23

Closed jhunovis closed 5 years ago

jhunovis commented 5 years ago

By default your Syncthing's web-interface will be enabled, not password protected and exposed to the public internet! This affects all home-servers which allow access to the HTTPS port from the internet!

You should either:

Exposing the unprotected admin interface allows any attacker to steal all of the users files, add extra (malicious files), or to modify any of the users files! Since vulnerable server can be found by simply trying the whole IP space this is critical!

yalh76 commented 5 years ago

Solved activating ldap authentication