提交 ae076bb4 编写于 作者: D Daniel P. Berrangé

remote: enforce ACL write permission for getting guest time & hostname

Getting the guest time and hostname both require use of guest agent
commands. These must not be allowed for read-only users, so the
permissions check must validate "write" permission not "read".

Fixes CVE-2019-3886
Reviewed-by: NJim Fehlig <jfehlig@suse.com>
Signed-off-by: NDaniel P. Berrangé <berrange@redhat.com>
上级 2a07c990
......@@ -5513,7 +5513,7 @@ enum remote_procedure {
/**
* @generate: both
* @acl: domain:read
* @acl: domain:write
*/
REMOTE_PROC_DOMAIN_GET_HOSTNAME = 277,
......@@ -5908,7 +5908,7 @@ enum remote_procedure {
/**
* @generate: none
* @acl: domain:read
* @acl: domain:write
*/
REMOTE_PROC_DOMAIN_GET_TIME = 337,
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册