[Trac] Re: Possible to bypass security using Ticket reports

2017-04-26 Thread RjOllos
On Tuesday, May 31, 2016 at 1:30:56 PM UTC-7, RjOllos wrote: > > > > On Friday, May 27, 2016 at 10:21:03 AM UTC-7, Javier Urien wrote: >> >> Hello Everyone, >> >> I just had a conversation with a colleague and figured that if a users >> has permissions REPORT_* (Not sure exactly the minimum,

[Trac] Re: Possible to bypass security using Ticket reports

2016-05-31 Thread RjOllos
On Friday, May 27, 2016 at 10:21:03 AM UTC-7, Javier Urien wrote: > > Hello Everyone, > > I just had a conversation with a colleague and figured that if a users > has permissions REPORT_* (Not sure exactly the minimum, but with > REPORT_ADMIN it works), the user can create a report and use