https://bugzilla.wikimedia.org/show_bug.cgi?id=46439
--- Comment #2 from Chris Steipp <[email protected]> --- The admin would obviously be able to impersonate other users, and have full access to everything in the db. I assume we trust our admins at that level. The other issue is what rights the db user that OTRS runs with on the db server. If the user had file permission, it could allow the admin (or anyone who gets the admin to run an xss/csrf, or brute forces their password) to start attacking the database server also. It looks like there are other critical services on that server/db, so the impact would be significant if an attack was successful. If there is a significant need for this to be enabled for a short period of time, and ops has the database user well restricted, and everyone is comfortable with the admins having that level of access to the data, then I think the benefit would probably outweigh the risk. -- You are receiving this mail because: You are on the CC list for the bug. You are the assignee for the bug. You are watching all bug changes. _______________________________________________ Wikibugs-l mailing list [email protected] https://lists.wikimedia.org/mailman/listinfo/wikibugs-l
