lukas-degan
Basic Pleskian
Username: lukas-degan
TITLE
<domain>/server-status is accessible when frame forwarding configured
PRODUCT, VERSION, OPERATING SYSTEM, ARCHITECTURE
Plesk Obsidian, Version 18.0.31 Update Nr. 2, Debian 10 64 Bit
PROBLEM DESCRIPTION
If hosting type of a domain is set to "frame forwarding", the apache status page under "https://<domain>/server-status" is public accessible. If its set for example to "permanent moved" it is not accessible.
And all this without any special manual configuration.
STEPS TO REPRODUCE
Set hosting type to "frame forwarding" and access the URL under: https://<domain>/server-status
ACTUAL RESULT
The Apache status page with many private information are accessible for everyone.
EXPECTED RESULT
The status page is not accessible without any explicit configuration.
ANY ADDITIONAL INFORMATION
YOUR EXPECTATIONS FROM PLESK SERVICE TEAM
Confirm bug
TITLE
<domain>/server-status is accessible when frame forwarding configured
PRODUCT, VERSION, OPERATING SYSTEM, ARCHITECTURE
Plesk Obsidian, Version 18.0.31 Update Nr. 2, Debian 10 64 Bit
PROBLEM DESCRIPTION
If hosting type of a domain is set to "frame forwarding", the apache status page under "https://<domain>/server-status" is public accessible. If its set for example to "permanent moved" it is not accessible.
And all this without any special manual configuration.
STEPS TO REPRODUCE
Set hosting type to "frame forwarding" and access the URL under: https://<domain>/server-status
ACTUAL RESULT
The Apache status page with many private information are accessible for everyone.
EXPECTED RESULT
The status page is not accessible without any explicit configuration.
ANY ADDITIONAL INFORMATION
YOUR EXPECTATIONS FROM PLESK SERVICE TEAM
Confirm bug