Skip to content

errors/local.xml and error page templates are publicly accessible #20209

Closed
@schmengler

Description

@schmengler

Preconditions (*)

All current Magento 2 versions:

  1. 2.3.0
  2. 2.2.7
  3. 2.1.16

Using default apache or nginx configuration with pub as doc root

Steps to reproduce (*)

For PHTML files:

  1. Point browser to /errors/default/page.phtml

For local.xml:

  1. Copy pub/errors/local.xml.sample to pub/errors/local.xml
  2. Point browser to /errors/local.xml

Expected result (*)

  1. A "not found" or "forbidden" response

Actual result (*)

  1. The source files are served

Metadata

Metadata

Assignees

Labels

Component: ConfigFixed in 2.2.xThe issue has been fixed in 2.2 release lineFixed in 2.3.xThe issue has been fixed in 2.3 release lineIssue: Clear DescriptionGate 2 Passed. Manual verification of the issue description passedIssue: ConfirmedGate 3 Passed. Manual verification of the issue completed. Issue is confirmedIssue: Format is validGate 1 Passed. Automatic verification of issue format passedIssue: Ready for WorkGate 4. Acknowledged. Issue is added to backlog and ready for developmentProgress: PR CreatedIndicates that Pull Request has been created to fix issueReproduced on 2.2.xThe issue has been reproduced on latest 2.2 releaseReproduced on 2.3.xThe issue has been reproduced on latest 2.3 release

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions