Repository navigation
Commit c5ca3c1
committed
Fix admins being able to update admin accounts with unauthorized groups.
If a non-superuser admin was allowed to update other admin accounts
within their group, and the admin also knew the UUID for another admin
group they were not authorized for, then they could assign admins to
that unauthorized admin group. Since exploiting this hinges upon a
limited admin knowing the UUIDs for other valid admin groups they can't
see, exploiting this should hopefully be difficult, but none the less, a
security issue.1 parent e9ccb78 commit c5ca3c1
2 files changed
Lines changed: 27 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
58 | 58 | | |
59 | 59 | | |
60 | 60 | | |
61 | | - | |
| 61 | + | |
62 | 62 | | |
63 | 63 | | |
64 | 64 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
107 | 107 | | |
108 | 108 | | |
109 | 109 | | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
110 | 136 | | |
111 | 137 | | |
112 | 138 | | |
| |||
0 commit comments