Skip to content
Snippets Groups Projects
  1. Oct 03, 2021
  2. Jun 16, 2021
  3. May 03, 2021
  4. Apr 08, 2021
  5. Oct 22, 2020
  6. Sep 23, 2020
  7. Sep 05, 2020
  8. Jun 17, 2020
  9. Jun 12, 2020
  10. Oct 13, 2019
  11. Sep 05, 2019
  12. Sep 01, 2019
  13. May 14, 2019
  14. Mar 24, 2019
  15. Feb 16, 2019
  16. Nov 18, 2018
  17. Nov 08, 2018
  18. Aug 17, 2018
  19. Aug 15, 2018
  20. Aug 14, 2018
  21. Jun 25, 2018
  22. May 30, 2018
  23. Apr 23, 2018
  24. Mar 21, 2018
  25. Mar 05, 2018
  26. Feb 28, 2018
  27. Feb 19, 2018
  28. Oct 20, 2017
  29. Jul 05, 2017
  30. Feb 10, 2017
    • Giancarlo Razzolini's avatar
      roles/*: Fix nginx log dir permissions · ff27e416
      Giancarlo Razzolini authored
      To correctly be safe for CVE-2016-1247, we need all nginx log dirs
      to be owned by both user and group root. Also, since nginx childs
      runs as http user, the directories permissions must be 0755, so the
      http user can descent into it. Since the logrotate will create the
      log files as http:log, the nginx childs will be able to write to the
      logs, but will not be able to create files inside those dirs, fully
      preventing CVE-2016-1247.
      Verified
      ff27e416
  31. Feb 05, 2017
  32. Jan 29, 2017
  33. Jan 26, 2017
Loading