Skip to content
Snippets Groups Projects
  1. Apr 18, 2022
  2. Oct 03, 2021
  3. Jun 16, 2021
  4. May 03, 2021
  5. Apr 08, 2021
  6. Oct 22, 2020
  7. Sep 23, 2020
  8. Sep 05, 2020
  9. Jun 17, 2020
  10. Jun 12, 2020
  11. Oct 13, 2019
  12. Sep 05, 2019
  13. Sep 01, 2019
  14. May 14, 2019
  15. Mar 24, 2019
  16. Feb 16, 2019
  17. Nov 18, 2018
  18. Nov 08, 2018
  19. Aug 17, 2018
  20. Aug 15, 2018
  21. Aug 14, 2018
  22. Jun 25, 2018
  23. May 30, 2018
  24. Apr 23, 2018
  25. Mar 21, 2018
  26. Mar 05, 2018
  27. Feb 28, 2018
  28. Feb 19, 2018
  29. Oct 20, 2017
  30. Jul 05, 2017
  31. Feb 10, 2017
    • Giancarlo Razzolini's avatar
      roles/*: Fix nginx log dir permissions · ff27e416
      Giancarlo Razzolini authored
      To correctly be safe for CVE-2016-1247, we need all nginx log dirs
      to be owned by both user and group root. Also, since nginx childs
      runs as http user, the directories permissions must be 0755, so the
      http user can descent into it. Since the logrotate will create the
      log files as http:log, the nginx childs will be able to write to the
      logs, but will not be able to create files inside those dirs, fully
      preventing CVE-2016-1247.
      Verified
      ff27e416
  32. Feb 05, 2017
  33. Jan 29, 2017
Loading