Security issue: user can copy page with only view permissions

XMLWordPrintable

    • Type: Bug
    • Resolution: Fixed
    • Priority: High
    • 2.5.5
    • Affects Version/s: 2.5.4
    • Component/s: None
    • Environment:

      Conf 2.5.4, Tomcat, Windows, SlqlServer

      I have a user who only has view permissions to a space.
      Logging on as that user, I went to the Info tab of a page.
      The Copy operation appeared, and I was able click the link, edit the copied page, and save it.

      This must be a security hole?

              Assignee:
              Samuel Le Berrigaud
              Reporter:
              Jon Nermut
              Votes:
              1 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: