Details
-
Bug
-
Status: Closed
-
Critical
-
Resolution: Fixed
-
5.1 EE SP4 (5.1.7), 5.2 EE SP3 (5.2.7)
-
All
Description
There is a security issue with PrincipalThreadLocal and PermissionThreadLocal which could allow a user to perform actions without the proper permissions. These two thread locales are not always reset, as a result, subsequent users could inherit the permission of the previous user.
Attachments
Issue Links
- is related to
-
LPS-7119 PrincipalThreadLocal and PermissionThreadLocal are not cleared after it is set
- Closed