Описание
Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it exposed to the internet (unless filtered by a firewall or reconfigured to listen to 127.0.0.1 only).
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| sphinxsearch | fixed | 2.2.11-4 | package |
Примечания
Issue is just with the default configuration, but can be easily reconfigured
to listen on localhost only. sphinxsearch will not be started automatically
and an admin needs first to create anyway a /etc/sphinxsearch/sphinx.conf
starting from a sample.
sphinxsearch should ideally update the defaults in sample configs to bind
listeners to localhost.
This is not treated as a vulnerability, subject to design choices for deployment
Связанные уязвимости
Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it exposed to the internet (unless filtered by a firewall or reconfigured to listen to 127.0.0.1 only).
Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it exposed to the internet (unless filtered by a firewall or reconfigured to listen to 127.0.0.1 only).
Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it exposed to the internet (unless filtered by a firewall or reconfigured to listen to 127.0.0.1 only).