Uploaded image for project: 'OpenNMS'
  1. OpenNMS
  2. NMS-6580

Security: downloadReport allow download and view any file in filesystem

    Details

      Description

      Walkthrough:

      • Login to OpenNMS Webui
        paste following URL in browser:
        http://<IP-OF-OPENNMS>:8980/opennms/report/database/downloadReport.htm?fileName=/etc/group

      Or another file in filesystem.

      It should be suppressed to access files outside defined paths.

        Attachments

          Activity

            People

            • Assignee:
              jeffg Jeff Gehlbach
              Reporter:
              mlaercher Martin Laercher
            • Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: