Re: pgsql: Fix search_path to a safe value during maintenance operations.

Поиск
Список
Период
Сортировка
От Jeff Davis
Тема Re: pgsql: Fix search_path to a safe value during maintenance operations.
Дата
Msg-id 578fb4be80247570e6a05924908765a0b345971e.camel@j-davis.com
обсуждение исходный текст
Ответ на Re: pgsql: Fix search_path to a safe value during maintenance operations.  (Robert Haas <robertmhaas@gmail.com>)
Список pgsql-committers
On Mon, 2023-06-19 at 16:03 -0400, Robert Haas wrote:
> I'm inclined to think that this is a real security issue and am not

Can you expand on that a bit? You mean a practical security issue for
the intended use cases?

> very sanguine about waiting another year to fix it, but at the same
> time, I'm somewhat worried that the proposed fix might be too narrow
> or wrongly-shaped. I'm not too convinced that we've properly
> understood what all of the problems in this area are. :-(

Would it be acceptable to document that the MAINTAIN privilege (along
with TRIGGER and, if I understand correctly, REFERENCES) carries
privilege escalation risk for the grantor?

Regards,
    Jeff Davis




В списке pgsql-committers по дате отправления:

Предыдущее
От: Andres Freund
Дата:
Сообщение: pgsql: fd.c: Retry after EINTR in more places
Следующее
От: Michael Paquier
Дата:
Сообщение: pgsql: Fix failure at promotion with 2PC transactions and archiving ena