Bug 1370584 - Capsule satellite reverse proxy allows everything including /pub and the UI
Summary: Capsule satellite reverse proxy allows everything including /pub and the UI
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Red Hat Satellite
Classification: Red Hat
Component: Capsule
Version: 6.2.0
Hardware: Unspecified
OS: Unspecified
medium
medium vote
Target Milestone: Unspecified
Assignee: satellite6-bugs
QA Contact: Katello QA List
URL:
Whiteboard:
Depends On:
Blocks: 1122832
TreeView+ depends on / blocked
 
Reported: 2016-08-26 16:21 UTC by Peter Vreman
Modified: 2020-04-15 14:38 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2018-09-04 18:06:06 UTC
Target Upstream Version:


Attachments (Terms of Use)

Description Peter Vreman 2016-08-26 16:21:54 UTC
Description of problem:
The Capsule reverse proxy to the Satellite is not limited to e.g. the API only. It allows full access all possible the Satellite data. This includes also the /var/www/html/pub directory under /pub. And also the UI.

A secret file in the pub on the satellite 

[crash] root@li-lc-1578:~# cat /var/www/html/pub/secret_dir/secret_file
secret file

On a client through capsule li-lc-1589 i can download the file from li-lc-1578

[crash] root@li-lc-1442:~# curl -k https://li-lc-1589.hag.hilti.com:8443/pub/secret_dir/secret_file
secret file


Version-Release number of selected component (if applicable):


How reproducible:


Steps to Reproduce:
1. Create a file in Satellite
mkdir -p /var/www/html/pub/secret_dir
echo "secret file" > /var/www/html/pub/secret_dir/secret_file
2. Download the file through the capsule https://capsule.com:8443/pub/secret_dir/secret_file.txt
3.

Actual results:


Expected results:


Additional info:

Comment 1 Peter Vreman 2016-08-26 16:27:24 UTC
Additional there is a special case for pulp-https that also does a reverse proxy for katello/api/repositories:

[crash] root@li-lc-1589:/etc/httpd/conf.d# grep -R ProxyPass
28-katello-reverse-proxy.conf:  ProxyPass / https://li-lc-1578.hag.hilti.com/
28-katello-reverse-proxy.conf:  ProxyPassReverse / /
28-katello-reverse-proxy.conf:  ProxyPassReverse / https://li-lc-1578.hag.hilti.com/
05-pulp-https.conf:  ProxyPass /katello/api/repositories/ https://li-lc-1578.hag.hilti.com/katello/api/repositories/
05-pulp-https.conf:    ProxyPassReverse https://li-lc-1578.hag.hilti.com/

Comment 5 Bryan Kearney 2018-09-04 18:06:06 UTC
Thank you for your interest in Satellite 6. We have evaluated this request, and we do not expect this to be implemented in the product in the foreseeable future. We are therefore closing this out as WONTFIX. If you have any concerns about this, please feel free to contact Rich Jerrido or Bryan Kearney. Thank you.


Note You need to log in before you can comment on or make changes to this bug.