cassandra-commits mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Aleksey Yeschenko (JIRA)" <j...@apache.org>
Subject [jira] [Created] (CASSANDRA-5144) Validate login for Thrift describe_keyspace, describe_keyspaces and set_keyspace methods
Date Thu, 10 Jan 2013 21:48:13 GMT
Aleksey Yeschenko created CASSANDRA-5144:
--------------------------------------------

             Summary: Validate login for Thrift describe_keyspace, describe_keyspaces and
set_keyspace methods
                 Key: CASSANDRA-5144
                 URL: https://issues.apache.org/jira/browse/CASSANDRA-5144
             Project: Cassandra
          Issue Type: Bug
    Affects Versions: 1.2.0
            Reporter: Aleksey Yeschenko
            Assignee: Aleksey Yeschenko
            Priority: Trivial
             Fix For: 1.2.1


Not validating login leaks info about keyspaces and columnfamilies if the configured authenticator
requires validation.

This change does not affect AllowAllAuthenticator, but if an implementation forbids anonymous
access, we should deny this information to unauthenticated users.

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators
For more information on JIRA, see: http://www.atlassian.com/software/jira

Mime
View raw message