The checkbox "Apply same permissions to all sub-items of this folder" in the document manager permissions modal is not taken into account and always considered as unchecked.
Impact
In situations where the permissions are being restricted some users might still keep, incorrectly, the possibility to edit or manage items. Only change made via the web UI are affected, changes directly made via the REST API are not impacted.
CVSSv3.1 score: 4.8 (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:H/A:N)
Exploitation
In the permissions modal of a folder, there is a checkbox "Apply same permissions to all sub-items of this folder" at the bottom of the modal.
When checked, the permissions should, as said, be applied to all the items (folder and documents) inside this folder.
The value of this checkbox is currently being ignored. Hence, the permissions are only set on the current folder, and not its descendants.
References
CWE 281
CVE-2024-39902