Skip to content

[ssl] possible Vuln. #20

Description

@Bizarrus

Currently, when certificates will be created, the system checks not the permission of domain (Does the user own the domain?), located at following Lines:

If a certificate is added manually, the certificate is currently not completely checked for validity:

Possible behavior

  • XSS may allow a certificate to be added to a domain even though the user currently logged in does not own this domain.
  • If the certificate is faulty (as it is not currently being intensively checked for validity), the apache2 web server may refuse to provide the service.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingsecuritysecurity behavior

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions