Skip to content

Default configuration binds to public ip when no private ip available #2296

Description

@Timer

As reported in #2295, we allow access from your public ip address if you do not have a private one available. This isn't a good default.

To remedy this, we should make sure the address passes:

/^(10|172|192)[.]/ || /^fd\w{2}:/

Activity

  1. added this to the 1.0.x milestone on May 20, 2017
  2. changed the title [-]Security concerns with binding to all interfaces[/-] [+]Default configuration binds to public ip when no private ip available[/+] on May 20, 2017
  3. added a commit that references this issue on May 20, 2017
    002ff10
  4. apaatsio commented on May 21, 2017

    @apaatsio
    Contributor

    That regex does not match private ip addresses correctly. For example 192.0.0.0 is not a private address.

  5. Timer commented on May 21, 2017

    @Timer
    ContributorAuthor

    Please see #2297 which has an appropriate match.

  6. added a commit that references this issue on May 21, 2017
    2430b56
  7. modified the milestones: 1.0.6, 1.0.x on Jun 6, 2017
  8. added a commit that references this issue on Jul 10, 2017
    59ffa84
  9. added a commit that references this issue on Aug 2, 2017
    6f3e256
  10. locked and limited conversation to collaborators on Jan 21, 2019
  11. added a commit that references this issue on Oct 8, 2024
    c0e328b
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions