Re: DoS Vulnerability - Mailing list pgsql-bugs

From David G. Johnston
Subject Re: DoS Vulnerability
Date
Msg-id CAKFQuwYnfsEKL1=M+LROeXTRRTC7EpLhyNP3ekizOHiiwq7GiA@mail.gmail.com
Whole thread Raw
In response to DoS Vulnerability  (emad al-mousa <emadalmousa2002@yahoo.com>)
List pgsql-bugs
On Tue, May 14, 2024, 10:12 emad al-mousa <emadalmousa2002@yahoo.com> wrote:

keeping connect permission by default granted to PUBLIC in PostgreSQL is opening a wide security hole that shouldn't exist in the first.

This isn't a bug nor a security issue, but I do concur that we should remove these defaults.  We've successfully (without being questioned why by users) done both public schema and createrole attribute changes in the past couple of years and this seems like a natural progression of secure defaults.


David J.

pgsql-bugs by date:

Previous
From: Tom Lane
Date:
Subject: Re: BUG #18463: Possible bug in stored procedures with polymorphic OUT parameters
Next
From: Tom Lane
Date:
Subject: Re: BUG #18463: Possible bug in stored procedures with polymorphic OUT parameters