Re: A little RLS oversight?

From: Alvaro Herrera <alvherre(at)2ndquadrant(dot)com>
To: Robert Haas <robertmhaas(at)gmail(dot)com>
Cc: Dean Rasheed <dean(dot)a(dot)rasheed(at)gmail(dot)com>, Michael Paquier <michael(dot)paquier(at)gmail(dot)com>, Stephen Frost <sfrost(at)snowman(dot)net>, Yaroslav <ladayaroslav(at)yandex(dot)ru>, PostgreSQL mailing lists <pgsql-hackers(at)postgresql(dot)org>
Subject: Re: A little RLS oversight?
Date: 2015-07-23 18:15:58
Message-ID: 20150723181558.GU5596@postgresql.org
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

Robert Haas wrote:
> On Wed, Jul 22, 2015 at 5:17 PM, Dean Rasheed <dean(dot)a(dot)rasheed(at)gmail(dot)com> wrote:
> > There's another issue here though -- just adding filters to the
> > pg_stats view won't prevent a determined user from seeing the contents
> > of the underlying table. For that, the view needs to have the
> > security_barrier property. Arguably the fact that pg_stats isn't a
> > security barrier view is a long-standing information leak allowing
> > users to see values from tables for which they don't have any
> > permissions. Is anyone concerned about that?
>
> Hrm. There's no help for that in the back-branches, but we should
> probably change it in 9.5+.

Perhaps not code-wise, but we could have a release note item suggesting
to run such-and-such command to plug the leak.

--
Álvaro Herrera http://www.2ndQuadrant.com/
PostgreSQL Development, 24x7 Support, Remote DBA, Training & Services

In response to

Browse pgsql-hackers by date

  From Date Subject
Next Message Robert Haas 2015-07-23 18:18:06 Re: BRIN index and aborted transaction
Previous Message Tom Lane 2015-07-23 18:14:47 Re: What is HeapScanDescData.rs_initblock good for?