Developer forum

Forum » Dynamicweb 9.0 Upgrade issues » Dynamicweb Security Issue TFS57874 29-11-2018

Dynamicweb Security Issue TFS57874 29-11-2018

Kevin O'Driscoll
Reply

Hi I got this alert and patch details, however the web.config fix:

"Remove the following configuration in web.config 
 <remove fileExtension=".log" /> <mimeMap fileExtension=".log" mimeType="text/plain" />   "

This prohibits any .log file from being opened from admin. If the " .. or upgrading to newest Dynamicweb version 9.3.14, 9.4.18 or 9.5.5." includes this fix the same thing will happen, loosing all use of internal log files.

I tried to limit access using the DW Permissions on EmailHandler folder, thinking only logged in Administrators can open and view log files, but no joy was given.

Can anyone tell me if the upgrade option has a workable solution? Or is a possible IIS solution available as an option?


Replies

 
Nicolai Pedersen
Reply

Yes it does - so currently you have to choose between convenience or security.

You can still download .log files from the admin and the open them.

BR Nicolai

 

You must be logged in to post in the forum