You are not logged in.

Announcement

 Téléchargez la dernière version stable de GLPI      -     Et vous, que pouvez vous faire pour le projet GLPI ? :  Contribuer
 Download last stable version of GLPI                      -     What can you do for GLPI ? :  Contribute

#1 2020-09-24 08:36:48

Klientos
Member
Registered: 2020-09-24
Posts: 4

Unsafe search results after upgrade to 9.5.1

Hi everyone

I've just updated GLPI to 9.5.1 (plus out-of-version mailcollector.class.php).

The issue is everyone can see any article in knowledge base search results, disregarding the permissions set ("Targets"). Articles in search results not filtered. If I search for article that I not allowed to read, I can read a part of that article in search results.
However, I cannot open an article itself (access denied), as expected.

Is it misconfiguration of update problem? Otherwise it should be classified as security issue. Maybe I should create aan issue on github?

Illustrating image: imgur.com/a/r9aIH43

Offline

Board footer

Powered by FluxBB