Uploaded image for project: 'Bitbucket Data Center'
  1. Bitbucket Data Center
  2. BSERV-3622

Elevation of global permission from Administrator to System administrator

    XMLWordPrintable

Details

    Description

      With "Administrator" permission I go to the global permissions page (http://<host>:7990/admin/permissions).

      1. Type in the name of another user without any global permissions.
      2. Select "System Administrator" as permission.
      3. Press save.

      Expected result:
      Stash would deny me creating a "System Administrator" since I am only a "Administrator".

      Actual result:
      Stash allows me to create a "System Administrator".

      Since I can create users I'm able to create a new user give that user "System Administrator" permissions, and then log in as that user. Thus elevating my privileges.

      Attachments

        Issue Links

          Activity

            People

              cofarrell CharlesA
              b41f49ee1bd3 Mads Tandrup
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: