Spring Beans 0day Vulnerability
Peter Schober
peter.schober at univie.ac.at
Wed Mar 30 12:59:20 UTC 2022
* Engström Per <per.engstrom at smhi.se> [2022-03-30 14:45]:
> I’ll take your advice and make our installation non-editable by the
> account running the application. Thanks Scott.
FWIW, this was always part of our local instructions for running the
IDP on Debian stable (currently v11, and Tomcat 9 and Java 11 that
come with it):
https://wiki.univie.ac.at/display/federation/include-file-system-permissions-v4
This is just an snippet included in various places (see the rest of
the docs for details) but in short this assumes an install performed
as root (i.e., there's room for further improvement) and you might
have to adjust the owner/groups involved to account for local
deployment differences.
-peter
More information about the users
mailing list