Commit ebc1244
Fix Unauthorised template/ISO list access to the domain/resource admins
In Apache CloudStack, while using the listTemplates and listIsos APIs, Domain Admins and Resource Admins can retrieve templates and ISOs outside their authorized scope when specifying the domainid parameter and the self or selfexecutable values in filter parameter. This results in unintended leakage of information related to those templates and ISOs. However, this issue does not affect accounts of the type User.
Co-authored-by: bernardodemarco <bernardomg2004@gmail.com>
Co-authored-by: nvazquez <nicovazquez90@gmail.com>1 parent 857ccb0 commit ebc1244
File tree
1 file changed
+1
-1
lines changed- server/src/main/java/com/cloud/api/query
1 file changed
+1
-1
lines changedLines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
4572 | 4572 | | |
4573 | 4573 | | |
4574 | 4574 | | |
4575 | | - | |
| 4575 | + | |
4576 | 4576 | | |
4577 | 4577 | | |
4578 | 4578 | | |
| |||
0 commit comments