Security holes in DefaultHierarchyManager and Content class
------------------------------------------------------------
Key: MAGNOLIA-1536
URL: http://jira.magnolia.info/browse/MAGNOLIA-1536
Project: Magnolia
Issue Type: Bug
Components: core
Affects Versions: 3.1 M1
Reporter: Sameer Charles
Assigned To: Sameer Charles
Priority: Critical
Fix For: 3.1 M2
- DefaultHierarchyManager.delete(String path) does not check for any permissions
- Content.deleteNodeData(String name) does not check for Permission.REMOVE
--
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators:
http://jira.magnolia.info/secure/Administrators.jspa
-
For more information on JIRA, see: http://www.atlassian.com/software/jira
----------------------------------------------------------------
for list details see
http://www.magnolia.info/en/developer.html
----------------------------------------------------------------