Comment 5 for bug 1472655

Revision history for this message
Amrith Kumar (amrith) wrote :

What is the "bug" here?

You grant a person super-user access, then you can assume that the person will do things that are permissible with that superuser access.

The implication of 'root access' is that once granted, the instance is tainted. Once root access is granted to an instance, it is forever 'root enabled'.

Therefore to claim that this is a security hole is, first of all, not a meaningful assumption.

I requested a bp (in my review) and I believe that there is more to consider here than merely changing one query. That is akin to applying Johnson and Johnson's finest Band Aid on the side of the HMS Titanic.