Project

General

Profile

Actions

Bug #15104

closed

A user with read only access can modify global parameters

Added by Benoît PECCATTE almost 5 years ago. Updated 9 months ago.

Status:
Released
Priority:
N/A
Category:
Security
Target version:
Severity:
Critical - prevents main use of Rudder | no workaround | data loss | security
UX impact:
User visibility:
Operational - other Techniques | Rudder settings | Plugins
Effort required:
Very Small
Priority:
0
Name check:
Reviewed
Fix check:
Error - Fixed
Regression:

Description

This is a security issue

Is seems that the user can also modify techniques in the editor.

Found in 5.0.11


Files


Subtasks 1 (0 open1 closed)

Bug #15904: "add global param" button still available for read-only roleReleasedNicolas CHARLESActions
Actions

Also available in: Atom PDF