You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@trafodion.apache.org by "Alice Chen (JIRA)" <ji...@apache.org> on 2015/07/22 20:19:10 UTC

[jira] [Created] (TRAFODION-948) LP Bug: 1414231 - Any user can cancel queries

Alice Chen created TRAFODION-948:
------------------------------------

             Summary: LP Bug: 1414231 - Any user can cancel queries
                 Key: TRAFODION-948
                 URL: https://issues.apache.org/jira/browse/TRAFODION-948
             Project: Apache Trafodion
          Issue Type: Bug
          Components: sql-security
            Reporter: Roberta Marton
            Assignee: Apache Trafodion
            Priority: Critical
             Fix For: 1.1 (pre-incubation)


Support for cancelling queries has been added for release 1.0.  However, with the current support, there is no privilege checking so anyone can cancel queries, even those that are not owned by the current user.  This is  a security gap.
Assigned to LaunchPad User Mike Hanlon



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)