Обсуждение: Potential Security Issue: Permissions in PgAdmin Installation Directory

Поиск
Список
Период
Сортировка

Potential Security Issue: Permissions in PgAdmin Installation Directory

От
Qasim Tahir
Дата:

Dear PgAdmin Community,

I am writing to report a potential security issue with the permissions set in the PgAdmin installation directory.

After installing PgAdmin, I observed that several directories, including 'bin', 'venv', and 'web', have 775 permissions. Here are the details of the directory permissions:image.png

Given the broad access provided by 775 permissions, there is a concern about the potential for unauthorized access or modifications. 


I would like to ask if these permissions are necessary for PgAdmin's operation or if they could be tightened to enhance security.

Your guidance on this matter would be greatly appreciated.

Thank you for your attention to this issue.


Best Regards,

Qasim Tahir

AGEDB

Вложения
Hi

On Thu, 30 May 2024 at 23:17, Qasim Tahir <qasimtahir.qt1@gmail.com> wrote:

Dear PgAdmin Community,

I am writing to report a potential security issue with the permissions set in the PgAdmin installation directory.

After installing PgAdmin, I observed that several directories, including 'bin', 'venv', and 'web', have 775 permissions. Here are the details of the directory permissions:image.png

Given the broad access provided by 775 permissions, there is a concern about the potential for unauthorized access or modifications. 


I would like to ask if these permissions are necessary for PgAdmin's operation or if they could be tightened to enhance security.

Your guidance on this matter would be greatly appreciated.

Thank you for your attention to this issue.


What platform and package is this exactly? 

--
Вложения
Akshay, could you or one of the team look into this please?

Thanks.

On Fri, 31 May 2024 at 23:27, Qasim Tahir <qasimtahir.qt1@gmail.com> wrote:
Hi,
Platform and package details are below

Platform: Rocky 8.9
pgadmin version:  8.7

Regards
Qasim

On Sat, Jun 1, 2024 at 3:09 AM Dave Page <dpage@pgadmin.org> wrote:
Hi

On Thu, 30 May 2024 at 23:17, Qasim Tahir <qasimtahir.qt1@gmail.com> wrote:

Dear PgAdmin Community,

I am writing to report a potential security issue with the permissions set in the PgAdmin installation directory.

After installing PgAdmin, I observed that several directories, including 'bin', 'venv', and 'web', have 775 permissions. Here are the details of the directory permissions:image.png

Given the broad access provided by 775 permissions, there is a concern about the potential for unauthorized access or modifications. 


I would like to ask if these permissions are necessary for PgAdmin's operation or if they could be tightened to enhance security.

Your guidance on this matter would be greatly appreciated.

Thank you for your attention to this issue.


What platform and package is this exactly? 

--


--
Вложения

Re: Potential Security Issue: Permissions in PgAdmin Installation Directory

От
Usman Khan
Дата:


On Sat, Jun 1, 2024 at 3:09 AM Dave Page <dpage@pgadmin.org> wrote:
Hi

On Thu, 30 May 2024 at 23:17, Qasim Tahir <qasimtahir.qt1@gmail.com> wrote:

Dear PgAdmin Community,

I am writing to report a potential security issue with the permissions set in the PgAdmin installation directory.

After installing PgAdmin, I observed that several directories, including 'bin', 'venv', and 'web', have 775 permissions. Here are the details of the directory permissions:image.png

Given the broad access provided by 775 permissions, there is a concern about the potential for unauthorized access or modifications. 


I would like to ask if these permissions are necessary for PgAdmin's operation or if they could be tightened to enhance security.

Your guidance on this matter would be greatly appreciated.

Thank you for your attention to this issue.


What platform and package is this exactly? 
FYI - this behaviour is reproducible on ubuntu 22.04 and rockey 8.9 with the latest installers for me.

ubuntu 22.04

image.png

rockey 8.9 - installed through guidance on this link https://www.pgadmin.org/download/pgadmin-4-rpm/

image.png




Вложения

Re: Potential Security Issue: Permissions in PgAdmin Installation Directory

От
Khushboo Vashi
Дата:


On Sat, Jun 1, 2024 at 8:34 PM Dave Page <dpage@pgadmin.org> wrote:
Akshay, could you or one of the team look into this please?
I am looking into this issue 

Thanks.

On Fri, 31 May 2024 at 23:27, Qasim Tahir <qasimtahir.qt1@gmail.com> wrote:
Hi,
Platform and package details are below

Platform: Rocky 8.9
pgadmin version:  8.7

Regards
Qasim

On Sat, Jun 1, 2024 at 3:09 AM Dave Page <dpage@pgadmin.org> wrote:
Hi

On Thu, 30 May 2024 at 23:17, Qasim Tahir <qasimtahir.qt1@gmail.com> wrote:

Dear PgAdmin Community,

I am writing to report a potential security issue with the permissions set in the PgAdmin installation directory.

After installing PgAdmin, I observed that several directories, including 'bin', 'venv', and 'web', have 775 permissions. Here are the details of the directory permissions:image.png

Given the broad access provided by 775 permissions, there is a concern about the potential for unauthorized access or modifications. 


I would like to ask if these permissions are necessary for PgAdmin's operation or if they could be tightened to enhance security.

Your guidance on this matter would be greatly appreciated.

Thank you for your attention to this issue.


What platform and package is this exactly? 

--


--
Вложения

Re: Potential Security Issue: Permissions in PgAdmin Installation Directory

От
Qasim Tahir
Дата:
Hi Everyone,

Any update regarding the issue.

Thanks
Qasim

On Mon, Jun 3, 2024 at 10:46 AM Khushboo Vashi <khushboo.vashi@enterprisedb.com> wrote:


On Sat, Jun 1, 2024 at 8:34 PM Dave Page <dpage@pgadmin.org> wrote:
Akshay, could you or one of the team look into this please?
I am looking into this issue 

Thanks.

On Fri, 31 May 2024 at 23:27, Qasim Tahir <qasimtahir.qt1@gmail.com> wrote:
Hi,
Platform and package details are below

Platform: Rocky 8.9
pgadmin version:  8.7

Regards
Qasim

On Sat, Jun 1, 2024 at 3:09 AM Dave Page <dpage@pgadmin.org> wrote:
Hi

On Thu, 30 May 2024 at 23:17, Qasim Tahir <qasimtahir.qt1@gmail.com> wrote:

Dear PgAdmin Community,

I am writing to report a potential security issue with the permissions set in the PgAdmin installation directory.

After installing PgAdmin, I observed that several directories, including 'bin', 'venv', and 'web', have 775 permissions. Here are the details of the directory permissions:image.png

Given the broad access provided by 775 permissions, there is a concern about the potential for unauthorized access or modifications. 


I would like to ask if these permissions are necessary for PgAdmin's operation or if they could be tightened to enhance security.

Your guidance on this matter would be greatly appreciated.

Thank you for your attention to this issue.


What platform and package is this exactly? 

--


--
Вложения

Re: Potential Security Issue: Permissions in PgAdmin Installation Directory

От
Khushboo Vashi
Дата:

On Mon, Jun 10, 2024 at 3:18 PM Qasim Tahir <qasimtahir.qt1@gmail.com> wrote:
Hi Everyone,

Any update regarding the issue.
We are working on this issue and it will be available in the next release, scheduled at the end of June.

Thanks
Qasim

On Mon, Jun 3, 2024 at 10:46 AM Khushboo Vashi <khushboo.vashi@enterprisedb.com> wrote:


On Sat, Jun 1, 2024 at 8:34 PM Dave Page <dpage@pgadmin.org> wrote:
Akshay, could you or one of the team look into this please?
I am looking into this issue 

Thanks.

On Fri, 31 May 2024 at 23:27, Qasim Tahir <qasimtahir.qt1@gmail.com> wrote:
Hi,
Platform and package details are below

Platform: Rocky 8.9
pgadmin version:  8.7

Regards
Qasim

On Sat, Jun 1, 2024 at 3:09 AM Dave Page <dpage@pgadmin.org> wrote:
Hi

On Thu, 30 May 2024 at 23:17, Qasim Tahir <qasimtahir.qt1@gmail.com> wrote:

Dear PgAdmin Community,

I am writing to report a potential security issue with the permissions set in the PgAdmin installation directory.

After installing PgAdmin, I observed that several directories, including 'bin', 'venv', and 'web', have 775 permissions. Here are the details of the directory permissions:image.png

Given the broad access provided by 775 permissions, there is a concern about the potential for unauthorized access or modifications. 


I would like to ask if these permissions are necessary for PgAdmin's operation or if they could be tightened to enhance security.

Your guidance on this matter would be greatly appreciated.

Thank you for your attention to this issue.


What platform and package is this exactly? 

--


--
Вложения

Re: Potential Security Issue: Permissions in PgAdmin Installation Directory

От
Khushboo Vashi
Дата:
Hello,

We have fixed this issue, you can test our nightly builds to verify the fix.
To test the nightly build,  follow the instructions given here https://www.postgresql.org/ftp/pgadmin/pgadmin4/snapshots/2024-06-12/apt/ .

Thanks,
Khushboo

On Mon, Jun 10, 2024 at 3:18 PM Qasim Tahir <qasimtahir.qt1@gmail.com> wrote:
Hi Everyone,

Any update regarding the issue.

Thanks
Qasim

On Mon, Jun 3, 2024 at 10:46 AM Khushboo Vashi <khushboo.vashi@enterprisedb.com> wrote:


On Sat, Jun 1, 2024 at 8:34 PM Dave Page <dpage@pgadmin.org> wrote:
Akshay, could you or one of the team look into this please?
I am looking into this issue 

Thanks.

On Fri, 31 May 2024 at 23:27, Qasim Tahir <qasimtahir.qt1@gmail.com> wrote:
Hi,
Platform and package details are below

Platform: Rocky 8.9
pgadmin version:  8.7

Regards
Qasim

On Sat, Jun 1, 2024 at 3:09 AM Dave Page <dpage@pgadmin.org> wrote:
Hi

On Thu, 30 May 2024 at 23:17, Qasim Tahir <qasimtahir.qt1@gmail.com> wrote:

Dear PgAdmin Community,

I am writing to report a potential security issue with the permissions set in the PgAdmin installation directory.

After installing PgAdmin, I observed that several directories, including 'bin', 'venv', and 'web', have 775 permissions. Here are the details of the directory permissions:image.png

Given the broad access provided by 775 permissions, there is a concern about the potential for unauthorized access or modifications. 


I would like to ask if these permissions are necessary for PgAdmin's operation or if they could be tightened to enhance security.

Your guidance on this matter would be greatly appreciated.

Thank you for your attention to this issue.


What platform and package is this exactly? 

--


--
Вложения

Re: Potential Security Issue: Permissions in PgAdmin Installation Directory

От
Qasim Tahir
Дата:
Yes, it worked. 

Thanks for your support

Regards
Qasim


On Wed, Jun 12, 2024 at 10:10 AM Khushboo Vashi <khushboo.vashi@enterprisedb.com> wrote:
Hello,

We have fixed this issue, you can test our nightly builds to verify the fix.
To test the nightly build,  follow the instructions given here https://www.postgresql.org/ftp/pgadmin/pgadmin4/snapshots/2024-06-12/apt/ .

Thanks,
Khushboo

On Mon, Jun 10, 2024 at 3:18 PM Qasim Tahir <qasimtahir.qt1@gmail.com> wrote:
Hi Everyone,

Any update regarding the issue.

Thanks
Qasim

On Mon, Jun 3, 2024 at 10:46 AM Khushboo Vashi <khushboo.vashi@enterprisedb.com> wrote:


On Sat, Jun 1, 2024 at 8:34 PM Dave Page <dpage@pgadmin.org> wrote:
Akshay, could you or one of the team look into this please?
I am looking into this issue 

Thanks.

On Fri, 31 May 2024 at 23:27, Qasim Tahir <qasimtahir.qt1@gmail.com> wrote:
Hi,
Platform and package details are below

Platform: Rocky 8.9
pgadmin version:  8.7

Regards
Qasim

On Sat, Jun 1, 2024 at 3:09 AM Dave Page <dpage@pgadmin.org> wrote:
Hi

On Thu, 30 May 2024 at 23:17, Qasim Tahir <qasimtahir.qt1@gmail.com> wrote:

Dear PgAdmin Community,

I am writing to report a potential security issue with the permissions set in the PgAdmin installation directory.

After installing PgAdmin, I observed that several directories, including 'bin', 'venv', and 'web', have 775 permissions. Here are the details of the directory permissions:image.png

Given the broad access provided by 775 permissions, there is a concern about the potential for unauthorized access or modifications. 


I would like to ask if these permissions are necessary for PgAdmin's operation or if they could be tightened to enhance security.

Your guidance on this matter would be greatly appreciated.

Thank you for your attention to this issue.


What platform and package is this exactly? 

--


--
Вложения