Uploaded image for project: 'Infinispan'
  1. Infinispan
  2. ISPN-15316

Security issue with admin and grant/deny

    XMLWordPrintable

Details

    • Bug
    • Resolution: Done
    • Major
    • 15.0.0.Dev05
    • 15.0.0.Dev04
    • REST
    • None

    Description

      Role mapping and grant deny, does not check is a user exists, simply responds with "self". in the case of implicit roles and creating an admin user, if we grant observer role to admin mapping, we can't access the server anymore since admin is mapped to observer instead of admin. This can cause potential mistakes by not having access to an admin user anymore.

      Attachments

        Activity

          People

            karestig@redhat.com Katia Aresti
            karestig@redhat.com Katia Aresti
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: