SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    Salesforce Forces Massive Outage as Result of Poorly Scripted Database Update - Security Put at Risk
Date    Sunday May 19 2019, @12:07AM
Author    martyb
Topic   
from the who-needs-QA-when-we-can-test-it-on-production dept.
https://soylentnews.org/article.pl?sid=19/05/18/0053205

datapharmer writes:

At around 9:15 UTC [17 May] Salesforce pushed a database script update that was intended to add modify all permissions to a specific internal profile used by their Pardot service. Due to a scripting error View and Modify All Objects Permission was granted to all user profiles for all organizations that ever had the Pardot product, including public facing community instances. This was of course a security nightmare for customers, especially those in the Financial and Health sectors, and an emergency change was pushed around 10:00 UTC to revoke all permissions to all profiles except for administrators. No announcement was made on their status sites due to the potential for bad actors to take advantage of the security issue that was introduced until the databases could be locked down. Further action was taken around 11:00 UTC to take down PODS completely, likely to further mitigate access risk which effectively expanded the outage to customers that never used Pardot but shared an instance with customers who did.

Salesforce is holding hourly calls, and recently admitted that the script had run both in their production PODS and also in the Passive Disaster Recovery Instances, complicating the ability to recover from the issue. There is currently no ETA for recovery, though it is still their hope that they will not have any data loss. They are beginning to bring back up instances, but only administrators will have access initially and it will require additional time before administrators will be able to modify permissions and rebuild profiles and there will be a longer wait yet before profile settings can be restored from backup.

Coverage at: Geekwire, The Register, and reddit


Original Submission

Links

  1. "datapharmer" - https://soylentnews.org/~datapharmer/
  2. "Geekwire" - https://www.geekwire.com/2019/database-error-causes-widespread-ongoing-salesforce-outage-affecting-pardot-customers/
  3. "The Register" - https://www.theregister.co.uk/2019/05/17/salesforce_database_outage/
  4. "reddit" - https://www.reddit.com/r/salesforce/comments/bpq336/salesforce_enables_modify_all_in_all_user_profiles/
  5. "Original Submission" - https://soylentnews.org/submit.pl?op=viewsub&subid=33846

© Copyright 2024 - SoylentNews, All Rights Reserved

printed from SoylentNews, Salesforce Forces Massive Outage as Result of Poorly Scripted Database Update - Security Put at Risk on 2024-03-29 12:34:16