Uploaded image for project: 'MariaDB Server'
  1. MariaDB Server
  2. MDEV-8276

Information leakage in information_schema TokuDB_* tables

    Details

      Description

      In information_schema in TokuDB_* tables every basic user with access can view other TokuDB databases, tables, keys names and some other minor information of ALL other users in current MySQL instance (including where user have NO access).

      I doubt that it's correct behaviour as other table types does not leak any information.

        Gliffy Diagrams

          Attachments

            Activity

            Hide
            elenst Elena Stepanova added a comment -

            Thanks for the report.

            Same with MySQL-5.5.41-TokuDB, so it's an upstream issue (upstream being TokuDB in this case). Assigning to Rich Prohaska to comment or decide on further action.

            Show
            elenst Elena Stepanova added a comment - Thanks for the report. Same with MySQL-5.5.41-TokuDB, so it's an upstream issue (upstream being TokuDB in this case). Assigning to Rich Prohaska to comment or decide on further action.

              People

              • Assignee:
                Unassigned
                Reporter:
                Profforg Alexander Loginov
              • Votes:
                0 Vote for this issue
                Watchers:
                3 Start watching this issue

                Dates

                • Created:
                  Updated: