•  
      request #32278 Removed project admin restricted users are not remove at project visibility switch
    Infos
    #32278
    Yannis ROSSETTO (rossettoy)
    2023-07-04 07:43
    2023-05-29 14:22
    33867
    Details
    Removed project admin restricted users are not remove at project visibility switch

    When switching from a project visibility that allows restricted users to Private without restricted, restricted users that are project administrators keep this access right.

    Impact

    Restricted users that were project administrators before the visibility switch keep the possibility to access the project and do some administration actions. CVSSv3.1 score: 4.1 (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L)

    References

    CWE 200
    OWASP Top 10 Broken Access Control
    CVE-2023-35938

    Project admin
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Yannis ROSSETTO (rossettoy)
    Closed
    2023-06-08
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2023-07-04 07:43

    CVE-2023-35938 has been assigned to this issue.


    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    User avatar
    Thomas Gerbet (tgerbet)2023-06-26 10:23
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    User avatar
    • Summary
      -Removed restricted users are not remove at project visibility switch 
      +Removed project admin restricted users are not remove at project visibility switch