Uploaded image for project: 'MidPoint'
  1. MidPoint
  2. MID-5265

Security of report expressions

    XMLWordPrintable

    Details

    • Type: Improvement
    • Status: Closed
    • Priority: Critical
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: 4.0
    • Component/s: None
    • Labels:
    • Milestone:
      M4

      Description

      Reporting expressions can be abused to gain high privileges - unless a very conservative system configuration is used.

      This is a first step to implement Expression Profiles

      https://wiki.evolveum.com/display/midPoint/Expression+Profiles

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              semancik Radovan Semancik
              Reporter:
              semancik Radovan Semancik
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved: