NAS-127981 / 24.10 / Restrict changes to SMB aux parameters to FULL_ADMIN (#13406) (#13436)
There are various parameters in which the administrator can provide
arbitrary commands and scripts to run via auxiliary parameters, some of
which may be executed as the root user. This can present a risk of
a limited administrator accidentally or intentionally performing actions
on the NAS with privileges that are higher than intended.
(cherry picked from commit 13769f030e37220a7d7b5e9c2b3f1e82c3a04951)
Co-authored-by: Andrew Walker <awalker at ixsystems.com>
NAS-127981 / 24.10 / Restrict changes to SMB aux parameters to FULL_ADMIN (#13406)
There are various parameters in which the administrator can provide
arbitrary commands and scripts to run via auxiliary parameters, some of
which may be executed as the root user. This can present a risk of
a limited administrator accidentally or intentionally performing actions
on the NAS with privileges that are higher than intended.
(cherry picked from commit 13769f030e37220a7d7b5e9c2b3f1e82c3a04951)
Restrict changes to SMB aux parameters to FULL_ADMIN
There are various parameters in which the administrator can provide
arbitrary commands and scripts to run via auxiliary parameters, some of
which may be executed as the root user. This can present a risk of
a limited administrator accidentally or intentionally performing actions
on the NAS with privileges that are higher than intended.
(cherry picked from commit d62c240e9f7cbd3c4bd686e3e20467626f6e1f43)
NAS-127981 / 24.10 / Restrict changes to SMB aux parameters to FULL_ADMIN (#13406)
There are various parameters in which the administrator can provide
arbitrary commands and scripts to run via auxiliary parameters, some of
which may be executed as the root user. This can present a risk of
a limited administrator accidentally or intentionally performing actions
on the NAS with privileges that are higher than intended.