Re: who can view pg_stat_activity? - Mailing list pgsql-admin

From Cory Nemelka
Subject Re: who can view pg_stat_activity?
Date
Msg-id CAMe5Gn3UO517TnjL2SgfCdFH0=OiKvA74d-Wgorp2E_6y4dS3Q@mail.gmail.com
Whole thread Raw
In response to Re: who can view pg_stat_activity?  (Shreeyansh Dba <shreeyansh2014@gmail.com>)
Responses Re: who can view pg_stat_activity?  (Don Seiler <don@seiler.us>)
List pgsql-admin
this seems to be a security hole.  this means I can see query text for queries that aren't mine.  anyone else concerned?

--cnemelka

On Wed, Feb 7, 2018 at 10:17 AM, Shreeyansh Dba <shreeyansh2014@gmail.com> wrote:
Hi Mark Steben,

There is no superuser required to view pg_stat_activity, a normal user can also view or access.




On Wed, Feb 7, 2018 at 10:27 PM, Mark Steben <mark.steben@drivedominion.com> wrote:
Good morning,

We currently run postgres 9.4.  The only way to view the pg_stat_activity view that I can see is that you must be a superuser.  I couldn't find anything in the documentation to confirm or refute this.  Could you please confirm if this is true or if not, what privileges are required?

Thank you for your time.


--



pgsql-admin by date:

Previous
From: Mark Steben
Date:
Subject: Re: who can view pg_stat_activity?
Next
From: Don Seiler
Date:
Subject: Re: who can view pg_stat_activity?