First published: Thu Jul 13 2017(Updated: )
A user can create a project named "myProject", use that project for a while and then delete it. After the original project is deleted, another user can create a project called "myProject". Since the subjectaccessreview will now pass for this second user, they will be able to access metrics from the original project.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Openshift | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.