Skip to content
Snippets Groups Projects
Giancarlo Razzolini's avatar
Giancarlo Razzolini authored
To correctly be safe for CVE-2016-1247, we need all nginx log dirs
to be owned by both user and group root. Also, since nginx childs
runs as http user, the directories permissions must be 0755, so the
http user can descent into it. Since the logrotate will create the
log files as http:log, the nginx childs will be able to write to the
logs, but will not be able to create files inside those dirs, fully
preventing CVE-2016-1247.
ff27e416
History
Code owners
Assign users and groups as approvers for specific file changes. Learn more.
Name Last commit Last update
..