Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

roles: ensure binaries are owned by root #373

Merged
merged 1 commit into from
Dec 31, 2023

Conversation

maxhoesel
Copy link
Collaborator

@maxhoesel maxhoesel commented Dec 30, 2023

This addresses a potentially security-critical issue described in #371 , where due to unchanged ownership, a normal user may have been able to modify/replace the step-cli and step-ca binaries.

@maxhoesel maxhoesel added pr-patch This PR introduces a bugfix (-> patch release) roles Something affecting one or more roles labels Dec 30, 2023
This addresses a potentially security-critical issue described in maxhoesel-ansible#374, where due to unchanged ownership, a normal user may have been able to modify/replace the step-cli and step-ca binaries.
@maxhoesel maxhoesel merged commit 0a97a47 into maxhoesel-ansible:main Dec 31, 2023
7 checks passed
@maxhoesel maxhoesel deleted the binary_permissions branch December 31, 2023 00:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
pr-patch This PR introduces a bugfix (-> patch release) roles Something affecting one or more roles
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant