[Koha-bugs] [Bug 23634] Privilege escalation vulnerability for staff users with 'edit_borrowers' permission and 'OpacResetPassword' enabled

2020-11-10 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=23634 Jonathan Druart changed: What|Removed |Added Keywords|rel_20_11_target| -- You are receiving th

[Koha-bugs] [Bug 23634] Privilege escalation vulnerability for staff users with 'edit_borrowers' permission and 'OpacResetPassword' enabled

2020-09-04 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=23634 Jonathan Druart changed: What|Removed |Added Blocks||26383 Referenced Bugs:

[Koha-bugs] [Bug 23634] Privilege escalation vulnerability for staff users with 'edit_borrowers' permission and 'OpacResetPassword' enabled

2020-09-03 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=23634 Jonathan Druart changed: What|Removed |Added Version(s)|20.11.00, 19.05.14, |20.11.00, 20.05.03,

[Koha-bugs] [Bug 23634] Privilege escalation vulnerability for staff users with 'edit_borrowers' permission and 'OpacResetPassword' enabled

2020-09-03 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=23634 Jonathan Druart changed: What|Removed |Added Version(s)|19.05.14, 19.11.09 |20.11.00, 19.05.14,

[Koha-bugs] [Bug 23634] Privilege escalation vulnerability for staff users with 'edit_borrowers' permission and 'OpacResetPassword' enabled

2020-09-03 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=23634 --- Comment #77 from Jonathan Druart --- Nothing to worry for stable branches, it will not change anything. -- You are receiving this mail because: You are watching all bug changes. ___

[Koha-bugs] [Bug 23634] Privilege escalation vulnerability for staff users with 'edit_borrowers' permission and 'OpacResetPassword' enabled

2020-09-03 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=23634 --- Comment #76 from Martin Renvoize --- I agree with this followup.. it makes a lot of sense to enforce a boolean return as aposed to leaking the hash as has_permission does. -- You are receiving this mail because: You are watchin

[Koha-bugs] [Bug 23634] Privilege escalation vulnerability for staff users with 'edit_borrowers' permission and 'OpacResetPassword' enabled

2020-09-03 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=23634 --- Comment #75 from Jonathan Druart --- Created attachment 109582 --> https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=109582&action=edit Bug 23634: Make is_superlibrarian return 1 or 0 -- You are receiving this mail

[Koha-bugs] [Bug 23634] Privilege escalation vulnerability for staff users with 'edit_borrowers' permission and 'OpacResetPassword' enabled

2020-08-31 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=23634 David Cook changed: What|Removed |Added See Also||https://bugs.koha-community

[Koha-bugs] [Bug 23634] Privilege escalation vulnerability for staff users with 'edit_borrowers' permission and 'OpacResetPassword' enabled

2020-08-31 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=23634 Lucas Gass changed: What|Removed |Added Group|Koha security | Status|Passed QA