Skip to content

Conversation

@wojcik91
Copy link
Contributor

@wojcik91 wojcik91 commented Sep 4, 2025

This pull request fixes vulnerability from penetration tests done by our security team on 2025-09-02:

Adjust permissions on Unix socket to make it available only to users belonging to a specific group.
Update all relevant packages to setup the group and add the user to it as part of the install process.

Partially resolves #551

@wojcik91 wojcik91 self-assigned this Sep 4, 2025
@wojcik91 wojcik91 changed the title Socket permissions restrict Unix socket permissions Sep 5, 2025
@wojcik91 wojcik91 changed the title restrict Unix socket permissions Fixes pentest issue DG25-27 from 2025-09-02 Sep 5, 2025
@wojcik91 wojcik91 marked this pull request as ready for review September 9, 2025 14:42
@wojcik91 wojcik91 merged commit f9c8d36 into release/1.5-alpha Sep 10, 2025
3 checks passed
@wojcik91 wojcik91 deleted the socket_permissions branch September 10, 2025 07:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants