Setting NoCursorTimeout flag in OP_QUERY should require special privilege.

XMLWordPrintableJSON

    • Server Security
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Disabling cursor timeout gives the client a means to force the server to leak resources. As such, it should require special privilege beyond "find".

            Assignee:
            [DO NOT USE] Backlog - Security Team
            Reporter:
            Andy Schwerin
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

              Created:
              Updated: