Openbravo Issue Tracking System - Openbravo ERP
View Issue Details
0002819Openbravo ERPC. Securitypublic2008-04-07 16:252008-06-19 19:43
user71 
alostale 
normalminoralways
closedfixed 
5
 
2.40alpha-r2 
No
Core
No
0002819: Security flaw in users setup
ubuntu 7.10
postgres 8.2.6
JDK 1.5
Tomcat 5.5
Openbravo 2.35 MP1

After creating a new client, log in as newclientAdmin

Go to General setup->Security->User

Click on the grid to view existing users. In addition to newclientAdmin and newclientUser both Openbravo and system are displayed.

Select Openbravo, click the password icon and change the password.

Logout and login as Openbravo, click the user info icon and you are able to change your role to any client on the system.

Oops.

Kind regards,

Andrew.
No tags attached.
Issue History
2008-06-19 19:43psarobeStatusresolved => closed

Notes
(0006408)
user71   
2005-06-01 00:00   
(edited on: 2008-06-12 09:43)
This bug was originally reported in SourceForge bug tracker and then migrated to Mantis.

You can see the original bug report in:
https://sourceforge.net/support/tracker.php?aid=1936766 [^]
(0003460)
alostale   
2008-05-12 12:19   
(edited on: 2008-06-12 09:25)
Logged In: YES
user_id=1500722
Originator: NO

Security review project solves this issue:

now Openbravo user is visible but not editable, so password is not changeable.