mirror of
https://github.com/empayre/fleet.git
synced 2024-11-06 08:55:24 +00:00
66e720d34d
The SMTP configuration could be used by an admin user to port scan the network the Fleet server was running on. This commit reduces the information possible to determine via this technique. A malicious admin can no longer determine whether any TCP server is listening on a given port/address. They can only determine ports and addresses where SMTP servers are running. Thanks to 'quikke' for reporting this vulnerability. |
||
---|---|---|
.. | ||
templates | ||
mail_test.go | ||
mail.go |