Return-Path: X-Original-To: apmail-cloudstack-issues-archive@www.apache.org Delivered-To: apmail-cloudstack-issues-archive@www.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id D45329C2D for ; Fri, 12 Dec 2014 10:27:13 +0000 (UTC) Received: (qmail 81041 invoked by uid 500); 12 Dec 2014 10:27:13 -0000 Delivered-To: apmail-cloudstack-issues-archive@cloudstack.apache.org Received: (qmail 81013 invoked by uid 500); 12 Dec 2014 10:27:13 -0000 Mailing-List: contact issues-help@cloudstack.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: dev@cloudstack.apache.org Delivered-To: mailing list issues@cloudstack.apache.org Received: (qmail 81004 invoked by uid 500); 12 Dec 2014 10:27:13 -0000 Delivered-To: apmail-incubator-cloudstack-issues@incubator.apache.org Received: (qmail 81001 invoked by uid 99); 12 Dec 2014 10:27:13 -0000 Received: from arcas.apache.org (HELO arcas.apache.org) (140.211.11.28) by apache.org (qpsmtpd/0.29) with ESMTP; Fri, 12 Dec 2014 10:27:13 +0000 Date: Fri, 12 Dec 2014 10:27:13 +0000 (UTC) From: "Wei Zhou (JIRA)" To: cloudstack-issues@incubator.apache.org Message-ID: In-Reply-To: References: Subject: [jira] [Closed] (CLOUDSTACK-5494) the dns resolver servers on the VRs are open to the world MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit X-JIRA-FingerPrint: 30527f35849b9dde25b450d4833f0394 [ https://issues.apache.org/jira/browse/CLOUDSTACK-5494?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Wei Zhou closed CLOUDSTACK-5494. -------------------------------- Resolution: Duplicate This issue has been already fixed by Sheng Yang https://git-wip-us.apache.org/repos/asf?p=cloudstack.git;h=a554ebd > the dns resolver servers on the VRs are open to the world > --------------------------------------------------------- > > Key: CLOUDSTACK-5494 > URL: https://issues.apache.org/jira/browse/CLOUDSTACK-5494 > Project: CloudStack > Issue Type: Bug > Security Level: Public(Anyone can view this level - this is the default.) > Affects Versions: 4.2.0, 4.3.0 > Reporter: Wei Zhou > Assignee: Jayapal Reddy > Priority: Critical > Labels: security > Fix For: Future > > > Currently the port 53 (tcp and udp) on virtual routers are open, so everyone on the internet can visit the dns service on virtual routers. This may cause overload and security issue. -- This message was sent by Atlassian JIRA (v6.3.4#6332)