Openbravo Issue Tracking System - Openbravo ERP
View Issue Details
0034492Openbravo ERPA. Platformpublic2016-11-14 13:462022-02-01 08:05
caristu 
Triage Platform Base 
highminoralways
acknowledgedopen 
5
 
 
Core
No
0034492: Review access for the StorePropertyActionHandler class
It is possible to set any property at any level (including system level) when invoking StorePropertyActionHandler
In description
security
Issue History
2016-11-14 13:46caristuNew Issue
2016-11-14 13:46caristuAssigned To => platform
2016-11-14 13:46caristuFile Added: curlSetProperty.txt
2016-11-14 13:46caristuModules => Core
2016-11-14 13:46caristuTriggers an Emergency Pack => No
2016-11-14 13:46caristuRelationship addedrelated to 0034490
2016-11-14 17:51caristuSummary[clustering] StorePropertyActionHandler is unsecure => [clustering] Review access for the StorePropertyActionHandler
2016-11-14 17:51caristuDescription Updatedbug_revision_view_page.php?rev_id=13704#r13704
2016-11-14 17:51caristuSteps to Reproduce Updatedbug_revision_view_page.php?rev_id=13706#r13706
2016-11-14 17:51caristuFile Deleted: curlSetProperty.txt
2016-11-14 17:51caristuSummary[clustering] Review access for the StorePropertyActionHandler => [clustering] Review access for the StorePropertyActionHandler class
2016-11-15 11:14caristuSummary[clustering] Review access for the StorePropertyActionHandler class => Review access for the StorePropertyActionHandler class
2016-11-16 16:39alostaleRelationship deletedrelated to 0034490
2016-12-01 12:18alostaleStatusnew => acknowledged
2016-12-01 13:20alostalePriorityhigh => normal
2016-12-01 14:03alostalePrioritynormal => high
2016-12-16 14:46caristuTag Attached: security
2022-02-01 08:05alostaleAssigned Toplatform => Triage Platform Base

There are no notes attached to this issue.