Anonymous | Login
Project:
RSS
  
News | My View | View Issues | Roadmap | Summary

View Issue DetailsJump to Notes ] Issue History ] Print ]
ID
0002819
TypeCategorySeverityReproducibilityDate SubmittedLast Update
defect[Openbravo ERP] C. Securityminoralways2008-04-07 16:252008-06-19 19:43
Reporteruser71View Statuspublic 
Assigned Toalostale 
PrioritynormalResolutionfixedFixed in Version2.40alpha-r2
StatusclosedFix in branchFixed in SCM revision
ProjectionnoneETAnoneTarget Version
OSAnyDatabaseAnyJava version
OS VersionDatabase versionAnt version
Product VersionSCM revision 
Merge Request Status
Review Assigned To
OBNetwork customerNo
Web browser
ModulesCore
Support ticket
Regression level
Regression date
Regression introduced in release
Regression introduced by commit
Triggers an Emergency PackNo
Summary

0002819: Security flaw in users setup

Descriptionubuntu 7.10
postgres 8.2.6
JDK 1.5
Tomcat 5.5
Openbravo 2.35 MP1

After creating a new client, log in as newclientAdmin

Go to General setup->Security->User

Click on the grid to view existing users. In addition to newclientAdmin and newclientUser both Openbravo and system are displayed.

Select Openbravo, click the password icon and change the password.

Logout and login as Openbravo, click the user info icon and you are able to change your role to any client on the system.

Oops.

Kind regards,

Andrew.
TagsNo tags attached.
Attached Files

- Relationships Relation Graph ] Dependency Graph ]

-  Notes
(0003460)
alostale (viewer)
2008-05-12 12:19
edited on: 2008-06-12 09:25

Logged In: YES
user_id=1500722
Originator: NO

Security review project solves this issue:

now Openbravo user is visible but not editable, so password is not changeable.
(0006408)
user71
2005-06-01 00:00
edited on: 2008-06-12 09:43

This bug was originally reported in SourceForge bug tracker and then migrated to Mantis.

You can see the original bug report in:
https://sourceforge.net/support/tracker.php?aid=1936766 [^]

- Issue History
Date Modified Username Field Change
2008-06-19 19:43 psarobe Status resolved => closed


Copyright © 2000 - 2009 MantisBT Group
Powered by Mantis Bugtracker