Re: Non-superuser subscription owners
От | Andres Freund |
---|---|
Тема | Re: Non-superuser subscription owners |
Дата | |
Msg-id | 20230203084748.odpbqaiil3lkyngq@alap3.anarazel.de обсуждение исходный текст |
Ответ на | Re: Non-superuser subscription owners (Robert Haas <robertmhaas@gmail.com>) |
Ответы |
Re: Non-superuser subscription owners
|
Список | pgsql-hackers |
Hi, On 2023-02-02 09:28:03 -0500, Robert Haas wrote: > I don't know what you mean by this. DML doesn't confer privileges. If > code gets executed and runs with the replication user's credentials, > that could lead to privilege escalation, but just moving rows around > doesn't, at least not in the database sense. Executing DML ends up executing code. Think predicated/expression indexes, triggers, default expressions etc. If a badly written trigger etc can be tricked to do arbitrary code exec, an attack will be able to run with the privs of the run-as user. How bad that is is influenced to some degree by the amount of privileges that user has. Greetings, Andres Freund
В списке pgsql-hackers по дате отправления: