Project

General

Profile

Actions

Bug #5473

closed

Make sure consumer can't change other than its own resources

Added by Ivan Necas about 10 years ago. Updated almost 6 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
-
Target version:
Difficulty:
Triaged:
Yes
Fixed in Releases:
Found in Releases:

Description

The consumer authrozition was being skipped, so the consumer certificate
could modify other's consumer related stuff.

Since this change was not released yet, not filling CVE for this one

Actions #1

Updated by Ivan Necas about 10 years ago

  • Status changed from Assigned to Ready For Testing
Actions #2

Updated by Ivan Necas about 10 years ago

  • Status changed from Ready For Testing to Closed
  • % Done changed from 0 to 100

Applied in changeset katello|commit:cb6b5bda884e6dae3806c2acd8db52433cddcdc3.

Actions #3

Updated by Eric Helms almost 10 years ago

  • Target version set to 44
Actions #4

Updated by Eric Helms almost 10 years ago

  • Triaged changed from No to Yes
Actions #5

Updated by Eric Helms over 9 years ago

  • translation missing: en.field_release set to 13
Actions

Also available in: Atom PDF