Project

General

Profile

Statistics
| Branch: | Tag: | Revision:
Name Size
report_host_permissions_test.rb 694 Bytes

Latest revisions

# Date Author Comment
d213e460 09/09/2015 11:37 AM Daniel Lobato Garcia

Fixes #11579 - Reports show/destroy restricted by host authorization (CVE-2015-5233)

ReportsController 'show' and 'destroy' now perform a check to see if
the User is authorized to see the Host associated with the Report. In
case it's not, it returns 404, as to not give hints whether a Report...

View revisions

Also available in: Atom