[AMOS commit] MDL-59969 admin: Warn admins if a development libs directory exists Committed into Git: 2017-08-29 17:01 UTC

[AMOS commit] MDL-59969 admin: Warn admins if a development libs directory exists Committed into Git: 2017-08-29 17:01 UTC

by AMOS bot -
Number of replies: 0
Author: David Mudrák
MDL-59969 admin: Warn admins if a development libs directory exists
We can't really control the direct web access to directories in dirroot,
that is part of the server setup. So we at least warn admins as they may
not realize the risks of having directories like vendor or node_modules
exposed.

Credit goes to Petr Škoda for mentioning the PHPUnit issue CVE-2017-9841
to me.


http://git.moodle.org/gw?p=moodle.git;a=commit;h=fad00feee6b7adae1824b3d9cc51a24cc64cb9bb
http://github.com/moodle/moodle/commit/fad00feee6b7adae1824b3d9cc51a24cc64cb9bb

+ 3.2 en [devlibdirpresent,core_admin]
+ 3.2 en [check_nodemodules_details,report_security]
+ 3.2 en [check_nodemodules_info,report_security]
+ 3.2 en [check_nodemodules_name,report_security]
+ 3.2 en [check_vendordir_details,report_security]
+ 3.2 en [check_vendordir_info,report_security]
+ 3.2 en [check_vendordir_name,report_security]