admin: reject clients unless their UID matches the current UID
The admin protocol RPC messages are only intended for use by the user running the daemon. As such they should not be allowed for any client UID that does not match the server UID. Fixes CVE-2019-10132 Reviewed-by: NJán Tomko <jtomko@redhat.com> Signed-off-by: NDaniel P. Berrangé <berrange@redhat.com>
Showing
-
mentioned in commit 39fb5ab3
-
mentioned in commit 8d121181
-
mentioned in commit 9bef4459
-
mentioned in commit acf17630
-
mentioned in commit ebc49c1d
-
mentioned in commit d1017aee
-
mentioned in commit 99decb0a
-
mentioned in commit dfd22fc5
-
mentioned in commit 4369e90f
-
mentioned in commit b0f788c2
-
mentioned in commit 78a00c53
-
mentioned in commit 44a0bcdb
-
mentioned in commit de48bfbe
-
mentioned in commit fd48a871
想要评论请 注册 或 登录