]> git.ipfire.org Git - thirdparty/asterisk.git/commit
manager.c: Prevent the Originate action from running the Originate app
authorGeorge Joseph <gjoseph@digium.com>
Thu, 24 Oct 2019 17:41:23 +0000 (11:41 -0600)
committerBenjamin Keith Ford <bford@digium.com>
Thu, 21 Nov 2019 20:37:29 +0000 (15:37 -0500)
commit94a831f72afe3c7ff0806848d731332ee49fc2d4
tree80c37a517e9ba0db1fc35d183f0f4523cf0cdb8e
parentfb53d3a79072ed172de6a0b88b801fdf9131d079
manager.c:  Prevent the Originate action from running the Originate app

If an AMI user without the "system" authorization calls the
Originate AMI command with the Originate application,
the second Originate could run the "System" command.

Action: Originate
Channel: Local/1111
Application: Originate
Data: Local/2222,app,System,touch /tmp/owned

If the "system" authorization isn't set, we now block the
Originate app as well as the System, Exec, etc. apps.

ASTERISK-28580
Reported by: Eliel SardaƱons

Change-Id: Ic4c9dedc34c426f03c8c14fce334a71386d8a5fa
(cherry picked from commit 1b9281a5ded62e5d30af2959e5aa33bc5a0fc285)
doc/UPGRADE-staging/AMI-Originate.txt [new file with mode: 0644]
main/manager.c