Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Dolibarr
  3. Persistent security warnings

Persistent security warnings

Scheduled Pinned Locked Moved Solved Dolibarr
8 Posts 4 Posters 1.4k Views 4 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S Offline
    S Offline
    shrey
    wrote on last edited by shrey
    #1

    All the users of the app see this persistent, security warning:

    659ee008-1830-496d-aa11-c165619b0f29-image.png

     Warning, your config file (htdocs/conf/conf.php) can be overwritten by the web server. This is a serious security hole. Modify permissions on file to be in read only mode for operating system user used by Web server. If you use Windows and FAT format for your disk, you must know that this file system does not allow to add permissions on file, so can't be completely safe. This security warning will remain active as long as the vulnerability is present.
    

    This seems unnecessary and a bit of a nuisance to not be able to remove it.

    What to do about this?

    1 Reply Last reply
    1
    • S Offline
      S Offline
      shrey
      wrote on last edited by shrey
      #2

      Also, this other warning:

      image.png

       Warning, once setup is finished, you must disable the installation/migration tools by adding a file install.lock into directory /app/data/dolibarr. Omitting the creation of this file is a grave security risk. This security warning will remain active as long as the vulnerability is present.
      

      I had removed this, by following the displayed instructions, but it seems, the install.lock got deleted automatically by Cloudron after some time/a restart.

      1 Reply Last reply
      0
      • nebulonN Offline
        nebulonN Offline
        nebulon
        Staff
        wrote on last edited by
        #3

        Strange I don't seem to be able to find the view in dolibarr where this would be shown. Tried a fresh installation. Can you give more instructions on how to reproduce this?

        1 Reply Last reply
        0
        • Y Offline
          Y Offline
          yurikous
          wrote on last edited by
          #4

          I search on forum and don't find answer.
          How to change permissions on files and folder.
          I got this message on Dolibarr : " Warning: your configuration file (htdocs/conf/conf.php) is writable by the Web server. This represents a serious security vulnerability. Change the permissions so that it is read-only for the account under which the Web server is running, and not readable for others."

          On forum I see that I have to give permission 640 but who and how ?
          I try this command on dolibarr terminal in contabo without success : chmod 644 conf.php

          Thanks

          1 Reply Last reply
          1
          • girishG Offline
            girishG Offline
            girish
            Staff
            wrote on last edited by
            #5

            @yurikous Thanks for reporting. This is a bug in the package. We are creating a new package with the fix.

            1 Reply Last reply
            0
            • Y Offline
              Y Offline
              yurikous
              wrote on last edited by
              #6

              Okay Nice. We are waiting so... Question, if I need to change permission of a folder or file, who I can make ?

              girishG 1 Reply Last reply
              0
              • Y yurikous

                Okay Nice. We are waiting so... Question, if I need to change permission of a folder or file, who I can make ?

                girishG Offline
                girishG Offline
                girish
                Staff
                wrote on last edited by
                #7

                @yurikous The file is in /run/dolibarr/conf . You can change the ownership of the file there via the Web Terminal.

                1 Reply Last reply
                0
                • girishG Offline
                  girishG Offline
                  girish
                  Staff
                  wrote on last edited by
                  #8

                  This should be fixed in the latest package.

                  1 Reply Last reply
                  0
                  • girishG girish has marked this topic as solved on
                  Reply
                  • Reply as topic
                  Log in to reply
                  • Oldest to Newest
                  • Newest to Oldest
                  • Most Votes


                  • Login

                  • Don't have an account? Register

                  • Login or register to search.
                  • First post
                    Last post
                  0
                  • Categories
                  • Recent
                  • Tags
                  • Popular
                  • Bookmarks
                  • Search