Actions
Defect #18159
closedSecurity issue when using local repositories
Status:
Closed
Priority:
High
Assignee:
-
Category:
Security
Target version:
-
Start date:
Due date:
% Done:
0%
Estimated time:
Resolution:
Duplicate
Affected version:
Description
Access to local repositories uses the system access rules. Since the system user used to run Redmine is unique, all local repositories must be accessible by this user. So, if a manager of one project knows the path to the repository of another project, he or she can configure a local repository for his/her own project using that path, obtaining reading access to that repository.
Related issues
Updated by Jean-Philippe Lang about 10 years ago
- Status changed from New to Closed
- Resolution set to Duplicate
Same as #10966.
Updated by Jean-Philippe Lang about 10 years ago
- Is duplicate of Feature #10966: [SECURITY] Project Managers should not be able to choose an URL for a local repository added
Actions