Last modified: 2013-01-24 23:08:18 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T41790, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 39790 - Sudo policy should use the project group, rather than ALL for users
Sudo policy should use the project group, rather than ALL for users
Status: RESOLVED FIXED
Product: MediaWiki extensions
Classification: Unclassified
OpenStackManager (Other open bugs)
unspecified
All All
: Unprioritized normal (vote)
: ---
Assigned To: Ryan Lane
:
Depends on:
Blocks: 39788
  Show dependency treegraph
 
Reported: 2012-08-30 01:54 UTC by Ryan Lane
Modified: 2013-01-24 23:08 UTC (History)
2 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Ryan Lane 2012-08-30 01:54:30 UTC
Using ALL for users, rather than the project group is insecure. If passwordless sudo was allowed, then all users on the system, including service accounts would be allowed to run sudo commands.
Comment 1 Andrew Bogott 2013-01-24 23:08:18 UTC
Fixed for new policies by https://gerrit.wikimedia.org/r/#/c/45481/

Fixed for old policies by hand.

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links