Accumulo
  1. Accumulo
  2. ACCUMULO-264

Users with the create permission but no tthe grant permission have the ability to create a new user with arbitrary scan authorizations

    Details

    • Type: Bug Bug
    • Status: Resolved
    • Priority: Major Major
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: 1.4.0
    • Component/s: client, master
    • Labels:

      Description

      Possible solutions- check both create and grant when doing an operation that does two actions
      OR
      only allow users to create a new user with a subset of their own authorizations.

        Activity

        Hide
        jv added a comment -

        We now through BAD_AUTHORIZATIONS if the new users permissions are not held by the creator, if the creator does not have ALTER_USER.

        Show
        jv added a comment - We now through BAD_AUTHORIZATIONS if the new users permissions are not held by the creator, if the creator does not have ALTER_USER.

          People

          • Assignee:
            Unassigned
            Reporter:
            John Vines
          • Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved:

              Development