Uploaded image for project: 'Crowd Data Center'
  1. Crowd Data Center
  2. CWD-3465

Crowd OpenID server does not enforce profile ownership for edits

XMLWordPrintable

      Crowd's OpenID server allows creation of different profiles. On modification, the security check for ownership of the profile is insufficient and may allow a malicious user to intentionally modify another user's profile.

              jwalton joe
              jwalton joe
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: