Health/Metrics/Debug endpoints publicly available without auth #13413
Labels
area/api
area/2.x
OSS 2.0 related issues and PRs
duplicate
kind/tech-debt
Needs cleanup, will make the developer experience better
security
Currently all
influxdb/http/handler.go
Lines 20 to 29 in 401ec79
are exposed publicly and do not require auth. This is likely to expose some amount of private data.
We should either
The text was updated successfully, but these errors were encountered: