YunoHost-Apps / wallabag_ynh

Wallabag v1 package for YunoHost
GNU Affero General Public License v3.0
5 stars 10 forks source link

[SECURITY] Wallabag database password readable by all users #25

Closed Jules-Bertholet closed 3 years ago

Jules-Bertholet commented 3 years ago

This password can be stored in $final_path/var/cache/prod/appProdProjectContainer.php, which all users can read.

lapineige commented 3 years ago

I suppose we should change the access rights for this file ?

Jules-Bertholet commented 3 years ago

Ideally the access rights for the whole folder should be restricted only to users that need the access.

lapineige commented 3 years ago

I wonder which users should have access…

Jules-Bertholet commented 3 years ago

Wait, I realized this issue is in the wrong repo, I meant it for wallabag2, I will close this and recreate it there