karaf-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Jean-Baptiste Onofré (JIRA) <j...@apache.org>
Subject [jira] [Updated] (KARAF-4993) Unsecured access to gogo console over web
Date Fri, 24 Feb 2017 08:05:44 GMT

     [ https://issues.apache.org/jira/browse/KARAF-4993?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]

Jean-Baptiste Onofré updated KARAF-4993:
----------------------------------------
    Fix Version/s: 4.0.9

> Unsecured access to gogo console over web
> -----------------------------------------
>
>                 Key: KARAF-4993
>                 URL: https://issues.apache.org/jira/browse/KARAF-4993
>             Project: Karaf
>          Issue Type: Bug
>          Components: karaf-webconsole
>    Affects Versions: 4.1.0, 3.0.8, 4.0.8
>            Reporter: Christian Schneider
>            Priority: Blocker
>             Fix For: 3.0.9, 4.0.9, 4.1.1
>
>
> Start plain karaf 4.1.0
> feature:install webconsole http-whiteboard
> Acess http://localhost:8181/gogo/
> Unsecured access to the gogo console
> If I use http://localhost:8181/gogo
> NPE http://apaste.info/wQTBD
> So it seems like the http whiteboard extender picks up the gogo webconsole plugin.
> Thanks to Kevin Schmidt for finding this issue.



--
This message was sent by Atlassian JIRA
(v6.3.15#6346)

Mime
View raw message