1.4 KiB
status, opened, located-in, fixed-by
| status | opened | located-in | fixed-by | |
|---|---|---|---|---|
| resolved | 2026-09-22 |
|
mesh-catalog multiple-fixes (the consumer's ACL user loses the dangerous command category); proven by the grant end-to-end bed, which now asserts a write outside the consumer's keys and FLUSHALL are refused |
080 — A cache grant lets the consumer flush the server
Symptom
The cache provider's provisioner creates each consumer an ACL user confined to keys under its own
login and allowed every command. A key pattern confines only commands that name keys. FLUSHALL,
FLUSHDB, CONFIG, SHUTDOWN and the rest of the dangerous category name none, so a consumer
granted "its own keys" could wipe every other consumer's, or stop the server.
Found by carrying the large mesh bed's retired tenancy assertions into the grant end-to-end bed:
FLUSHALL as the consumer answered OK.
Why it matters beyond the instance
A grant is the mesh's promise that a consumer gets what it asked for and nothing else. The promise was checked on the key pattern and never on the command set, and the one bed that had asked was retired before it was run against the catalogue's module.
What would close it
The ACL user is allowed the ordinary command set minus the dangerous category, and the grant bed
asserts a write outside the consumer's keys and a FLUSHALL are both refused.