diff options
author | Neil Blakey-Milner <nbm@FreeBSD.org> | 2002-03-23 10:04:29 +0000 |
---|---|---|
committer | Neil Blakey-Milner <nbm@FreeBSD.org> | 2002-03-23 10:04:29 +0000 |
commit | be5a1dcb666cecc7961fc9d42a1cffbb86f0713b (patch) | |
tree | 7770358271199bd906bc465b08a545dfff68ad06 /www/web2ldap/files/patch-ag | |
parent | Update to 1.63 (diff) |
Implement the HotFix described at
http://www.zope.org/Products/Zope/Hotfix_2002-03-01/README.txt which
says:
``The issue involves the checking of security for objects with proxy
roles. The context of the owner user that created the object with
proxy roles was not being taken into account when determining access
to the object with proxy roles. This flaw could allow users defined
in subfolders of a site with sufficient privileges to access objects
at higher levels in the site that they would not normally be able to
access.''
PR: 36103
Submitted by: HAYASHI Yasushi <yasi@yasi.to>
Notes
Notes:
svn path=/head/; revision=56470
Diffstat (limited to 'www/web2ldap/files/patch-ag')
0 files changed, 0 insertions, 0 deletions