Re: pgsql: Fix search_path to a safe value during maintenance operations. - Mailing list pgsql-committers

From Jeff Davis
Subject Re: pgsql: Fix search_path to a safe value during maintenance operations.
Date
Msg-id 578fb4be80247570e6a05924908765a0b345971e.camel@j-davis.com
Whole thread Raw
In response to Re: pgsql: Fix search_path to a safe value during maintenance operations.  (Robert Haas <robertmhaas@gmail.com>)
List pgsql-committers
On Mon, 2023-06-19 at 16:03 -0400, Robert Haas wrote:
> I'm inclined to think that this is a real security issue and am not

Can you expand on that a bit? You mean a practical security issue for
the intended use cases?

> very sanguine about waiting another year to fix it, but at the same
> time, I'm somewhat worried that the proposed fix might be too narrow
> or wrongly-shaped. I'm not too convinced that we've properly
> understood what all of the problems in this area are. :-(

Would it be acceptable to document that the MAINTAIN privilege (along
with TRIGGER and, if I understand correctly, REFERENCES) carries
privilege escalation risk for the grantor?

Regards,
    Jeff Davis




pgsql-committers by date:

Previous
From: Andres Freund
Date:
Subject: pgsql: fd.c: Retry after EINTR in more places
Next
From: Michael Paquier
Date:
Subject: pgsql: Fix failure at promotion with 2PC transactions and archiving ena