Bug #19704
closed
Upcoming security fix in Foreman breaks KeepCurrentUser middleware
Added by Marek Hulán over 7 years ago.
Updated over 6 years ago.
Description
Katello tests failures revealed KeepCurrentUser middleware can fail when stored user is admin. It seems that org/loc scope is not restored and the admin won't be found when the change from #19612 will be present (planned for Foreman 1.15.1).
- Related to Bug #19612: CVE-2017-7505: User scoped in organization with permissions for user management can manage administrators that are not assigned to any organization added
- Related to Bug #19664: Upcoming security fix in Foreman breaks Katello tests added
- Status changed from New to Ready For Testing
- Pull request https://github.com/theforeman/foreman-tasks/pull/252 added
- Status changed from Ready For Testing to Closed
- % Done changed from 0 to 100
- Translation missing: en.field_release set to 252
- Related to Bug #20040: Can't create new product added
Also available in: Atom
PDF