Potential Security Issue: Permissions in PgAdmin Installation Directory

From: Qasim Tahir <qasimtahir(dot)qt1(at)gmail(dot)com>
To: pgadmin-hackers(at)postgresql(dot)org
Subject: Potential Security Issue: Permissions in PgAdmin Installation Directory
Date: 2024-05-31 06:17:27
Message-ID: CAG=GPUPva4=hFdQNGwke2auE6sL0kVW6hb2bSxbWE4xdtWe93A@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgadmin-hackers

Dear PgAdmin Community,

I am writing to report a potential security issue with the permissions set
in the PgAdmin installation directory.

After installing PgAdmin, I observed that several directories, including
'bin', 'venv', and 'web', have 775 permissions. Here are the details of the
directory permissions:
[image: image.png]

Given the broad access provided by 775 permissions, there is a concern
about the potential for unauthorized access or modifications.

I would like to ask if these permissions are necessary for PgAdmin's
operation or if they could be tightened to enhance security.

Your guidance on this matter would be greatly appreciated.

Thank you for your attention to this issue.

Best Regards,

Qasim Tahir

AGEDB

Responses

Browse pgadmin-hackers by date

  From Date Subject
Next Message Muhammad Ikram 2024-05-31 06:21:12 Re: Pgadmin 4 cannot add or modify line in a view
Previous Message Amitabh Kant 2024-05-31 02:05:23 Re: Pgadmin 4 cannot add or modify line in a view