Project

General

Profile

Statistics
| Branch: | Tag: | Revision:
Name Size
report_host_permissions_test.rb 694 Bytes

Latest revisions

# Date Author Comment
be0b9bee 09/15/2015 09:33 AM Daniel Lobato Garcia

Fixes #11579 - Reports show/destroy restricted by host authorization (CVE-2015-5233)

ReportsController 'show' and 'destroy' now perform a check to see if
the User is authorized to see the Host associated with the Report. In
case it's not, it returns 404, as to not give hints whether a Report...

View revisions

Also available in: Atom