Uploaded image for project: 'Couchbase Server'
  1. Couchbase Server
  2. MB-8047

babysitter cookie is passed to child ns_server in the open

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • Blocker
    • 2.1.0
    • 2.1.0
    • ns_server
    • Security Level: Public
    • None

    Description

      SUBJ. I just realized that the way babysitter passes cookie to itself to ns_server is visible in ps output to unprivileged users. That's clearly insecure as it allows full access to erlang guts to anybody with access to box running couchbase server.

      Attachments

        No reviews matched the request. Check your Options in the drop-down menu of this sections header.

        Activity

          People

            alkondratenko Aleksey Kondratenko (Inactive)
            alkondratenko Aleksey Kondratenko (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Gerrit Reviews

                There are no open Gerrit changes

                PagerDuty