Actions
Bug #28855
closedDatabase template finder ignores taxonomy
Description
When unattended controller renders a template, it finds it in a correct taxonomy in method provisioning_template, but then it is passed into the renderer outside of the taxonomy block in TemplateRendering#render_template. Therefore all snippets being loaded via SnippetRendering#snippet (source.find_snippet(name)) is called without Taxonomy handling (basically unscoped SQL query). This is possibly a security issue as well when all snippets are essentially shared across all organizations even when taxonomy is not set like that.
Updated by The Foreman Bot about 4 years ago
- Status changed from New to Ready For Testing
- Assignee set to Lukas Zapletal
- Pull request https://github.com/theforeman/foreman/pull/7386 added
Updated by Lukas Zapletal about 4 years ago
- Status changed from Ready For Testing to Rejected
Actions