-
- Downloads
Merge branch 'security-65756-ex-admin-attacker-can-comment-in-internal-12-2' into '12-2-stable'
Improper access control allows the attacker to comment in internal commit after they are no longer admin See merge request gitlab/gitlabhq!3392
No related branches found
No related tags found
Showing
- app/policies/commit_policy.rb 1 addition, 0 deletionsapp/policies/commit_policy.rb
- changelogs/unreleased/security-65756-ex-admin-attacker-can-comment-in-internal.yml 5 additions, 0 deletions...urity-65756-ex-admin-attacker-can-comment-in-internal.yml
- spec/policies/commit_policy_spec.rb 36 additions, 12 deletionsspec/policies/commit_policy_spec.rb
Please register or sign in to comment