Disable portal-app default page 06/72306/1
authorParshad Patel <pars.patel@samsung.com>
Thu, 8 Nov 2018 07:01:30 +0000 (16:01 +0900)
committerManoop Talasila <talasila@research.att.com>
Fri, 9 Nov 2018 14:42:43 +0000 (14:42 +0000)
Fix for Security: disable portal-app default page that targets tomcat 8.0.37 specific exploits issue
Fix default tomcat webapps removal command in Dockerfile.portal

Issue-ID: PORTAL-303
Change-Id: I9be563f0d824f687271fbdcf12e5785ff18ab83f
Signed-off-by: Parshad Patel <pars.patel@samsung.com>
(cherry picked from commit de1cfb5dfea79d17c6224264abd483271b8ae27e)

deliveries/Dockerfile.portal

index 9b9f548..a2a143c 100644 (file)
@@ -30,7 +30,7 @@ RUN wget -q http://archive.apache.org/dist/tomcat/tomcat-8/v8.0.37/bin/apache-to
 RUN tar -xzf ${TOMCATTAR}
 RUN rm ${TOMCATTAR}
 # Remove manager and sample apps
-RUN rm -fr ${TOMCAT}/webapps/[a-z]*
+RUN rm -fr ${TOMCAT}/webapps/*
 RUN mkdir -p /opt
 COPY ${SERVERXML} ${TOMCAT}/conf
 RUN mv ${TOMCAT} /opt