Skip to content

Latest commit

 

History

History
33 lines (22 loc) · 716 Bytes

nflx-2016-003.md

File metadata and controls

33 lines (22 loc) · 716 Bytes
Advisory ID:

NFLX-2016-003

Advisory Title:

zuul.filter.admin.enabled Defaults to True.

Author:

Julian Vilas / [email protected]

Scott Behrens / [email protected]

Release Date:

08/31/2016

Application:

Zuul

Release:

1.x Branch

Source:

https://github.com/Netflix/zuul

Severity:

Critical

Overview:

Zuul was configured with zuul.filter.admin.enabled to True, which can be used to upload filters via the default application port which may result in Remote Code Execution (RCE).

Patch:

The 1.x branch contains the fix. The commit can be found here: https://github.com/Netflix/zuul/commit/d1e683427223920994dbf4809fed8c9479d9a6a8