Possible to bypass security using Ticket reports

16 views
Skip to first unread message

Javier Urien

unread,
May 27, 2016, 1:21:03 PM5/27/16
to Trac Users
Hello Everyone,

  I just had a conversation with a colleague and figured that if a users has permissions REPORT_* (Not sure exactly the minimum, but with REPORT_ADMIN it works), the user can create a report and use SQL to access every table on the system.
  Is there a way to prevent this?

Regards.

RjOllos

unread,
May 31, 2016, 4:30:56 PM5/31/16
to Trac Users
The only mitigation I'm aware of is to only give `REPORT_MODIFY` and `REPORT_CREATE` to trusted users.

It's worth considering to allow reports to be restricted to a configurable subset of tables.

I also wonder whether we should have a permission level that allows users to save a Query as a report, but not allow them to add SQL to a report. 

- Ryan

RjOllos

unread,
Apr 26, 2017, 6:26:42 PM4/26/17
to Trac Users
Reply all
Reply to author
Forward
0 new messages