•  
      request #38675 Recursive permissions to document manager folder are not properly applied
    Infos
    #38675
    Thomas Gorka (tgorka)
    2024-07-22 13:44
    2024-07-09 14:59
    40304
    Details
    Recursive permissions to document manager folder are not properly applied

    The checkbox "Apply same permissions to all sub-items of this folder" in the document manager permissions modal is not taken into account and always considered as unchecked.

    Impact

    In situations where the permissions are being restricted some users might still keep, incorrectly, the possibility to edit or manage items. Only change made via the web UI are affected, changes directly made via the REST API are not impacted.

    CVSSv3.1 score: 4.8 (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:H/A:N)

    Exploitation

    In the permissions modal of a folder, there is a checkbox "Apply same permissions to all sub-items of this folder" at the bottom of the modal.

    When checked, the permissions should, as said, be applied to all the items (folder and documents) inside this folder.

    The value of this checkbox is currently being ignored. Hence, the permissions are only set on the current folder, and not its descendants.

    References

    CWE 281
    CVE-2024-39902

    Doc/Documentation manager
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Thomas Gorka (tgorka)
    Closed
    2024-07-10
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2024-07-11 08:58
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    User avatar
    Thomas Gerbet (tgerbet)2024-07-09 16:00
    • Summary
      -"Apply permissions to all sub-items" should not be ignored  
      +Recursive permissions to document manager folder are not properly applied 
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes