Even worse. Every packager (not a member of package) is able to orphan *any* package and drop the main admin there. Just verified it. On Thu, Mar 18, 2021 at 11:25 AM Miro Hrončok <mhroncok@xxxxxxxxxx> wrote: > > On 18. 03. 21 11:14, Pavel Zhukov wrote: > > So... Looks like the ex-admin of the package was able to orphan one > > somehow and by doing this drop the current admin from the member > > list. Looks like a bug if not a security hole for me. > > An "admin" can remove admins. I don't think that is necessarily an unexpected > permission of an admin. > > I'd argue that the security hole lies in keeping users you don't trust as admins. > > -- > Miro Hrončok > -- > Phone: +420777974800 > IRC: mhroncok > -- Pavel Zhukov Software Engineer IRC: landgraf _______________________________________________ devel mailing list -- devel@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to devel-leave@xxxxxxxxxxxxxxxxxxxxxxx Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/devel@xxxxxxxxxxxxxxxxxxxxxxx Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure