Actions
Bug #36097
closedUser without view_provisioning_templates permission is able to see the rendered template
Description
On Hosts -> Review template page, its possible for user to see the rendered template - even that the user doesn't have the view_provisioning_templates permission.
As rendered template may contain passwords or other data which should be protected, it should not be possible to see the rendered template without having the view_provisioning_templates right.
Updated by The Foreman Bot almost 2 years ago
- Status changed from New to Ready For Testing
- Assignee set to Bernhard Suttner
- Pull request https://github.com/theforeman/foreman/pull/9624 added
Updated by Bernhard Suttner over 1 year ago
- Status changed from Ready For Testing to Closed
Applied in changeset foreman|d620319bf62c7047ca06d1c8a7cc6154105315a5.
Updated by Ewoud Kohl van Wijngaarden over 1 year ago
- Category set to Security
- Triaged changed from No to Yes
Actions