-
Notifications
You must be signed in to change notification settings - Fork 32
Closed
Labels
bugSomething isn't workingSomething isn't workingdirectorIssue relating to the director componentIssue relating to the director componentinternalInternal code improvements, not user-facingInternal code improvements, not user-facing
Description
Pelican Service:
- Client
- Plugin
- Registry
- Director
- Origin
- Cache
- Other (please give the detail)
When working through the redirectToOrigin API looking into direct reads, @jhiemstrawisc and I discovered a potential vulnerability within the redirectToOrigin. A user can bypass the directread check and talk directly to an origin using another client by simply utilizing the api call /api/v1.0/director/origin. This would allow users to not set directreads but talk directly to an origin anyway and could lead to exploitation of the origin.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
bugSomething isn't workingSomething isn't workingdirectorIssue relating to the director componentIssue relating to the director componentinternalInternal code improvements, not user-facingInternal code improvements, not user-facing