Skip to content

Commit 51d92be

Browse files
author
Till Brehm
committed
Merge branch '559-dev' into 'develop'
Fix dontlog vulnerability (Backport from !559) See merge request ispconfig/ispconfig3!1165
2 parents 5f31eb1 + d0e89c4 commit 51d92be

File tree

2 files changed

+4
-4
lines changed

2 files changed

+4
-4
lines changed

install/tpl/apache_ispconfig.conf.master

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -12,10 +12,10 @@ SetEnvIf Request_URI "^/datalogstatus.php$" dontlog
1212

1313
LogFormat "%v %h %l %u %t \"%r\" %>s %O \"%{Referer}i\" \"%{User-Agent}i\"" combined_ispconfig
1414
<tmpl_if name='logging' op='==' value='anon'>
15-
CustomLog "| /usr/local/ispconfig/server/scripts/vlogger -p -s access.log -t \"%Y%m%d-access.log\" /var/log/ispconfig/httpd" combined_ispconfig env=!dontlog
15+
CustomLog "| /usr/local/ispconfig/server/scripts/vlogger -p -s access.log -t \"%Y%m%d-access.log\" /var/log/ispconfig/httpd" combined_ispconfig
1616
</tmpl_if>
1717
<tmpl_if name='logging' op='==' value='yes'>
18-
CustomLog "| /usr/local/ispconfig/server/scripts/vlogger -s access.log -t \"%Y%m%d-access.log\" /var/log/ispconfig/httpd" combined_ispconfig env=!dontlog
18+
CustomLog "| /usr/local/ispconfig/server/scripts/vlogger -s access.log -t \"%Y%m%d-access.log\" /var/log/ispconfig/httpd" combined_ispconfig
1919
</tmpl_if>
2020

2121
<Directory /var/www/clients>

server/conf/apache_ispconfig.conf.master

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,10 +7,10 @@ SetEnvIf Request_URI "^/datalogstatus.php$" dontlog
77

88
LogFormat "%v %h %l %u %t \"%r\" %>s %O \"%{Referer}i\" \"%{User-Agent}i\"" combined_ispconfig
99
<tmpl_if name='logging' op='==' value='anon'>
10-
CustomLog "| /usr/local/ispconfig/server/scripts/vlogger -p -s access.log -t \"%Y%m%d-access.log\" /var/log/ispconfig/httpd" combined_ispconfig env=!dontlog
10+
CustomLog "| /usr/local/ispconfig/server/scripts/vlogger -p -s access.log -t \"%Y%m%d-access.log\" /var/log/ispconfig/httpd" combined_ispconfig
1111
</tmpl_if>
1212
<tmpl_if name='logging' op='==' value='yes'>
13-
CustomLog "| /usr/local/ispconfig/server/scripts/vlogger -s access.log -t \"%Y%m%d-access.log\" /var/log/ispconfig/httpd" combined_ispconfig env=!dontlog
13+
CustomLog "| /usr/local/ispconfig/server/scripts/vlogger -s access.log -t \"%Y%m%d-access.log\" /var/log/ispconfig/httpd" combined_ispconfig
1414
</tmpl_if>
1515

1616
<Directory /var/www/clients>

0 commit comments

Comments
 (0)