-
Bug
-
Resolution: Done-Errata
-
Major
-
4.13, 4.12
-
None
-
Quality / Stability / Reliability
-
False
-
-
None
-
None
-
No
-
None
-
None
-
None
-
+
-
Done
-
Bug Fix
-
-
None
-
None
-
None
-
None
Description of problem:
User can impersonate to all the user without the appropriate rolebinding
Version-Release number of selected component (if applicable):
How reproducible:
Steps to Reproduce:
1. Login OCP as cluster-admin, and assign cluster-reader role to the user (eg: testuser-0) 2. Impersonate User <username> on the Users page (User list --> click on three dots --> click on "Impersonate User <Username>") 3. Go to User page again, check if the 'Impersonate User <username>' option is enabled 4. Move the user into a group, and do the same steps(1-3)
Actual results:
Expected results:
Additional info:
- blocks
-
OCPBUGS-24352 [release-4.14] User can impersonate to all the user without the appropriate rolebinding
-
- Closed
-
- is cloned by
-
OCPBUGS-24352 [release-4.14] User can impersonate to all the user without the appropriate rolebinding
-
- Closed
-
- links to
-
RHSA-2023:7198 OpenShift Container Platform 4.15 security update