From: | Alvaro Herrera <alvherre(at)2ndquadrant(dot)com> |
---|---|
To: | Robert Haas <robertmhaas(at)gmail(dot)com> |
Cc: | Dean Rasheed <dean(dot)a(dot)rasheed(at)gmail(dot)com>, Michael Paquier <michael(dot)paquier(at)gmail(dot)com>, Stephen Frost <sfrost(at)snowman(dot)net>, Yaroslav <ladayaroslav(at)yandex(dot)ru>, PostgreSQL mailing lists <pgsql-hackers(at)postgresql(dot)org> |
Subject: | Re: A little RLS oversight? |
Date: | 2015-07-23 18:15:58 |
Message-ID: | 20150723181558.GU5596@postgresql.org |
Views: | Raw Message | Whole Thread | Download mbox | Resend email |
Thread: | |
Lists: | pgsql-hackers |
Robert Haas wrote:
> On Wed, Jul 22, 2015 at 5:17 PM, Dean Rasheed <dean(dot)a(dot)rasheed(at)gmail(dot)com> wrote:
> > There's another issue here though -- just adding filters to the
> > pg_stats view won't prevent a determined user from seeing the contents
> > of the underlying table. For that, the view needs to have the
> > security_barrier property. Arguably the fact that pg_stats isn't a
> > security barrier view is a long-standing information leak allowing
> > users to see values from tables for which they don't have any
> > permissions. Is anyone concerned about that?
>
> Hrm. There's no help for that in the back-branches, but we should
> probably change it in 9.5+.
Perhaps not code-wise, but we could have a release note item suggesting
to run such-and-such command to plug the leak.
--
Álvaro Herrera http://www.2ndQuadrant.com/
PostgreSQL Development, 24x7 Support, Remote DBA, Training & Services
From | Date | Subject | |
---|---|---|---|
Next Message | Robert Haas | 2015-07-23 18:18:06 | Re: BRIN index and aborted transaction |
Previous Message | Tom Lane | 2015-07-23 18:14:47 | Re: What is HeapScanDescData.rs_initblock good for? |