Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Insecure install #41

Open
Rudd-O opened this issue Mar 14, 2017 · 0 comments
Open

Insecure install #41

Rudd-O opened this issue Mar 14, 2017 · 0 comments

Comments

@Rudd-O
Copy link

Rudd-O commented Mar 14, 2017

https://github.com/William-Yeh/ansible-prometheus/blob/master/tasks/main.yml#L34

makes the /opt/prometheus directory mode 750 and owned by user prometheus, which is exactly the wrong thing to do. The files must be owned by root so that, in the case of compromise of any service running as user prometheus, the attacker (running as user prometheus) cannot modify any part of /opt/prometheus.

Please fix this security issue. Thank you very much.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant