Custom Query (2152 matches)

Filters
 
Or
 
  
 
Columns

Show under each result:


Results (100 - 102 of 2152)

Ticket Resolution Summary Owner Reporter
#132 fixed Security hole - read package/group list (REST) rgrp dread

Reported by dread, 5 years ago.

Description

Using REST interface you can list packages and groups without authorization being checked.

Can be fixed using more advanced query to check authz.

#133 fixed Security hole - search package/group (WUI & REST) rgrp dread

Reported by dread, 5 years ago.

Description

Using WUI or REST interface you can search packages and groups without authorization being checked.

On the REST interface you can also read all the attributes of the packages using the 'all-fields' option.

Can be fixed using more advanced query to check authz.

#134 fixed admin interface is only available to sysadmins rgrp dread
Note: See TracQuery for help on using queries.