RubyFlow The Ruby and Rails community linklog

×

The Ruby and Rails community linklog

Made a library? Written a blog post? Found a useful tutorial? Share it with the Ruby community here or just enjoy what everyone else has found!

I Ran a Security Scanner Against Mastodon, Discourse, and Chatwoot's AWS Defaults. He

I used Stave, an open-source configuration safety tool, to answer those questions for three of the most popular open-source Rails applications: Mastodon (47K stars), Discourse (43K stars), and Chatwoot (22K stars).

The results: 47 security findings across three projects. Two of the three default to publicly readable S3 buckets. None configure encryption, access logging, or Public Access Block.

This isn’t a vulnerability disclosure. These projects work exactly as documented. The problem is the documentation. Full details:

https://dev.to/bala_paranj_059d338e44e7e/i-ran-a-security-scanner-against-mastodon-discourse-and-chatwoots-aws-defaults-heres-what-i-32pe

Post a comment

You can use basic HTML markup (e.g. <a>) or Markdown.

As you are not logged in, you will be
directed via GitHub to signup or sign in