Skip to content

cpp/potential-system-data-exposure: Does printing a username from getpwuid() count as potential exposure of sensitive system data? #12409

Open
@ryao

Description

@ryao

https://github.com/ryao/zfs/security/code-scanning/824

https://github.com/ryao/zfs/blob/3881dd42bbfb7297f08e796c38b35d54e11ac500/cmd/zpool/zpool_main.c#L9431-L9431

Does telling a user his own username really count as potential exposure of sensitive information?

I guess this could be dependent on your threat model since a threat model for an IoT device is certainly different from a threat model for a standard multi-user system. However, I wonder if a username, which is public information in most threat models for C/C++ software, really should be counted as sensitive information by cpp/potential-system-data-exposure.

Metadata

Metadata

Assignees

No one assigned

    Labels

    questionFurther information is requested

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions