AsiaBSDCon 2017 Secure CGI

CGI security model

CGI security model

CGI security mechanism
CGI's inheritance-based security model.

CGI applications have a well-defined (but unstandardised) tradition of having the security model set by the web server. This is usually in the form of privilege dropping, although file-system jailing is popular.

Undefined (and relevant):