Skip to content

Doorman 0.4.1 - security fix

Compare
Choose a tag to compare
@mwielgoszewski mwielgoszewski released this 31 May 13:40
· 223 commits to master since this release

Doorman v0.4.1 release addresses a security flaw in Doorman. When using an authentication backend, an unauthenticated user may access a node's osquery status logs by browsing directly to the HTTP endpoint at https://<hostname>/manage/node/<node id>/logs.

  • Added @login_required decorator to the node logs endpoint

Commits since last release

Commits to master since this release.