Grouper WS allows unauthorized users to delete attribute assignments

XMLWordPrintable

    • Type: Bug
    • Resolution: Fixed
    • Priority: Major
    • 1.6.4, 2.0.4, 2.1.5
    • Affects Version/s: 1.6.3, 2.0.3, 2.1.4
    • Component/s: WS
    • None

      This could be possible if the authorized user knows the attribute assignment id, which they could get if they have read only access.

            Assignee:
            Shilen Patel
            Reporter:
            Shilen Patel
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: