<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[After todays update: serious security config errors!]]></title><description><![CDATA[<p dir="auto">Just updated Matomo to the latest app version and this is the red security warning:</p>
<p dir="auto">Required Private Directories 	<a href="https://analytics.domain.tld/config/config.ini.php" target="_blank" rel="noopener noreferrer nofollow ugc">https://analytics.domain.tld/config/config.ini.php</a><br />
<a href="https://analytics.domain.tld/lang/en.json" target="_blank" rel="noopener noreferrer nofollow ugc">https://analytics.domain.tld/lang/en.json</a><br />
We found that the above URLs are accessible via the browser, but they should NOT be. Allowing them to be accessed can pose a potential security risk since the contents can provide information about your server and potentially your users. Please restrict access to them.</p>
<p dir="auto">We also found that Matomo's config directory is publicly accessible. While attackers can't read the config now, if your webserver stops executing PHP files for some reason, your MySQL credentials and other information will be available to anyone. Please check your webserver config and deny access to this directory.</p>
]]></description><link>https://forum.cloudron.io/topic/5080/after-todays-update-serious-security-config-errors</link><generator>RSS for Node</generator><lastBuildDate>Thu, 16 Apr 2026 05:57:20 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/5080.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 17 May 2021 20:25:20 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to After todays update: serious security config errors! on Tue, 18 May 2021 19:37:25 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nebulon" aria-label="Profile: nebulon">@<bdi>nebulon</bdi></a> thanks!!!!!</p>
]]></description><link>https://forum.cloudron.io/post/31515</link><guid isPermaLink="true">https://forum.cloudron.io/post/31515</guid><dc:creator><![CDATA[imc67]]></dc:creator><pubDate>Tue, 18 May 2021 19:37:25 GMT</pubDate></item><item><title><![CDATA[Reply to After todays update: serious security config errors! on Tue, 18 May 2021 19:23:26 GMT]]></title><description><![CDATA[<p dir="auto">I've released a new package right now, which fixes this issue.</p>
]]></description><link>https://forum.cloudron.io/post/31513</link><guid isPermaLink="true">https://forum.cloudron.io/post/31513</guid><dc:creator><![CDATA[nebulon]]></dc:creator><pubDate>Tue, 18 May 2021 19:23:26 GMT</pubDate></item><item><title><![CDATA[Reply to After todays update: serious security config errors! on Tue, 18 May 2021 15:27:48 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/imc67" aria-label="Profile: imc67">@<bdi>imc67</bdi></a> <a class="plugin-mentions-user plugin-mentions-a" href="/user/nebulon" aria-label="Profile: nebulon">@<bdi>nebulon</bdi></a> I can confirm I see this as well after it updated last night. But you're right, it wasn't there before so if the package wasn't changed to allow those files pubiclly then perhaps the Matomo update added that extra security check. Either way it should be fixed though. Hopefully it won't be too difficult to resolve.</p>
]]></description><link>https://forum.cloudron.io/post/31486</link><guid isPermaLink="true">https://forum.cloudron.io/post/31486</guid><dc:creator><![CDATA[d19dotca]]></dc:creator><pubDate>Tue, 18 May 2021 15:27:48 GMT</pubDate></item><item><title><![CDATA[Reply to After todays update: serious security config errors! on Tue, 18 May 2021 15:24:44 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/imc67" aria-label="Profile: imc67">@<bdi>imc67</bdi></a> thanks for the heads up, looking into this now. We haven't changed anything in the package config as such, so maybe those were always accessible?</p>
]]></description><link>https://forum.cloudron.io/post/31485</link><guid isPermaLink="true">https://forum.cloudron.io/post/31485</guid><dc:creator><![CDATA[nebulon]]></dc:creator><pubDate>Tue, 18 May 2021 15:24:44 GMT</pubDate></item></channel></rss>