Skip to content
This repository has been archived by the owner on Apr 26, 2024. It is now read-only.

Debian package: sqlite db, media and logs are world-readable by default #10008

Closed
MRAAGH opened this issue May 18, 2021 · 1 comment
Closed
Labels
A-Packaging Our Debian packages, docker images; or issues relevant to downstream packagers good first issue Good for newcomers Security T-Task Refactoring, removal, replacement, enabling or disabling functionality, other engineering tasks.

Comments

@MRAAGH
Copy link

MRAAGH commented May 18, 2021

The following files and directories are world-readable by default:

  • /var/lib/matrix-synapse/
  • /var/lib/matrix-synapse/homeserver.db
  • /var/lib/matrix-synapse/media/
  • /var/log/matrix-synapse/homeserver.log

All of these contain sensitive user information and should not be world-readable!

Installation package: matrix-synapse-py3 from packages.matrix.org
Synapse version: {"server_version":"1.33.2","python_version":"3.7.3"}
OS: Debian 10

Related issues:

@erikjohnston erikjohnston added Security T-Task Refactoring, removal, replacement, enabling or disabling functionality, other engineering tasks. labels May 20, 2021
@richvdh richvdh added A-Packaging Our Debian packages, docker images; or issues relevant to downstream packagers good first issue Good for newcomers labels Jul 14, 2021
@richvdh
Copy link
Member

richvdh commented Jul 14, 2021

I think this is a dup of #2955

@richvdh richvdh closed this as completed Jul 14, 2021
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
A-Packaging Our Debian packages, docker images; or issues relevant to downstream packagers good first issue Good for newcomers Security T-Task Refactoring, removal, replacement, enabling or disabling functionality, other engineering tasks.
Projects
None yet
Development

No branches or pull requests

3 participants