Log in
Skip to main content
Skip to sidebar
jira.ucar.edu
Dashboards
Projects
Issues
Capture
Getting started
Create
Give feedback to Atlassian
Help
Jira Core help
Keyboard Shortcuts
About Jira
Jira Credits
Log In
Gateway
GTWY-1093
Security audit of the database
Log In
Done
Export
null
XML
Word
Printable
Details
Type:
Technical Work
Resolution:
Done
Priority:
Major
Fix Version/s:
1.3.0-M1
,
1.3.0
Affects Version/s:
None
Component/s:
Security
Labels:
None
Description
It is likely that the permissions for the database are wide open, meaning any user can do anything. The DB should be audited to ensure the permissions are setup to something that would be appropriate and defensible.
Attachments
Easy Agile Planning Poker
Sub-Tasks
Options
Show All
Show Open
Bulk operation
Open issue navigator
1.
Externalize database credentials.
Done
Unassigned
2.
Correct database owner should be established during database creation.
Done
Unassigned
3.
Update installation and update scripts to accept installation specific role names (not hard coded)
Done
Nathan Hook
4.
Establish list of needed database access roles
Done
Nathan Hook
5.
No security constraints applied to the database
Done
Nathan Hook
6.
Document the changes required for database creation and gateway configuration
Done
Nathan Hook
Activity
People
Assignee:
Nathan Hook
Reporter:
Nathan Wilhelmi (Inactive)
Votes:
0
Vote for this issue
Watchers:
1
Start watching this issue
Dates
Created:
21/Dec/09 10:19 AM
Updated:
17/Nov/15 2:15 PM
Resolved:
22/Feb/11 11:05 AM