Ex: Re: SSPCPP-961

Paul B. Henson henson at cpp.edu
Thu Mar 9 02:04:18 UTC 2023


> From: Cantor, Scott
> Sent: Wednesday, March 8, 2023 5:22 AM
>
> That's why I didn't want to do it. The intent as Rod said was not to do that on
> upgrades, so please file a bug.

Done.
 
> I simply didn't have the time to keep arguing with the guy about it, but I did
> warn him that at the first sign of trouble, it was getting pulled.

Doesn't Jira have a "CLOSED WONTFIX" option :)? Dunno. It's not like the installation instructions didn't call it out, but on the other hand, how many Windows administrators are going to go back and tune up ACLs by hand after they double-click the installer?

If random authenticated users can in general access your server you're in a bad situation to begin with. The primary thing I could see happening with this is if somebody got a remote compromise with low privileges they could potentially escalate by doing this, but on the other hand, depending on the patch level of the server, they would have quite the menu of bundled vulnerabilities to choose from.



More information about the users mailing list