Uploaded image for project: 'PUBLIC - Liferay Portal Enterprise Edition'
  1. PUBLIC - Liferay Portal Enterprise Edition
  2. LPE-1919

Users can perform actions without the proper permissions

Details

    Description

      There is a security issue with PrincipalThreadLocal and PermissionThreadLocal which could allow a user to perform actions without the proper permissions. These two thread locales are not always reset, as a result, subsequent users could inherit the permission of the previous user.

      Attachments

        Issue Links

          Activity

            People

              john.jiang John Wayne Jiang (Inactive)
              brian.chan Brian Chan
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Packages

                  Version Package
                  5.1 EE SP5 (5.1.8)
                  5.2 EE SP4 (5.2.8)