Bug 1806521

Summary: Not strict restrictive permissions in the doc folders: slf4j
Product: Red Hat Enterprise Linux 7 Reporter: Denis Volkov <dvolkov>
Component: slf4jAssignee: Java maintainers <java-maint>
Status: CLOSED UPSTREAM QA Contact: RHEL Stacks Subsystem QE <rhel-stacks-subsystem-qe>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 7.8CC: jorton
Target Milestone: rc   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2020-02-26 10:38:17 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Denis Volkov 2020-02-24 12:37:31 UTC
Description of problem:
Files in documentation folder have 'loose' permissions:
    In the file /usr/share/doc/slf4j-1.7.4/APACHE-LICENSE , the permission is 0664. 0755 is expected or more restrictive

Version-Release number of selected component (if applicable):
    slf4j-1.7.4-4.el7_4.noarch

Additional info:
Customer has security checker that complains about loose permissions for tomcat documentation files. Customer is concerned that group-write permissions to the documentation files may affect the security of the system and requesting for removing write permissions on group.

Comment 2 Joe Orton 2020-02-26 10:38:17 UTC
Thanks for the report.  Although the permissions could be changed, we are not currently planning to update this component.  Since the file's group is also root there is no obvious security issue here and 0664/root.root 0644/root.root are functionally equivalent.

We'll correct this upstream for future releases.