https://bugzilla.suse.com/show_bug.cgi?id=1215873 https://bugzilla.suse.com/show_bug.cgi?id=1215873#c3 Matthias Gerstner <matthias.gerstner@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Assignee|security-team@suse.de |matthias.gerstner@suse.com Status|NEW |IN_PROGRESS --- Comment #3 from Matthias Gerstner <matthias.gerstner@suse.com> --- The thermald D-Bus interface is only accessible to root and to members of the "power" group. By default there are no members of the power group. In the original audit bug is has been pointed out that it is important that this stays this way, because some of the API endpoints are not suitable for access by everybody. The new whitelisting will be coupled to the D-Bus configuration content, so if it changes we will notice, thus the danger that something worseness here without us noticing is reduced. -- You are receiving this mail because: You are on the CC list for the bug.