Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-22460

No warning when granting XWiki.ComponentClass programming right

    XMLWordPrintable

Details

    • Unknown
    • N/A

    Description

      Steps to reproduce:

      1. As a user without programming right, add an object of type XWiki.ComponentClass to a page
      2. Try editing this page as a user with programming right.

      Expected result:

      There is a warning that editing will grant programming right to the component.

      Actual result:

      There is no warning.

      Note: I'm currently not sure about the security impact. This can be used at best to break some existing component. It is not really possible to actually execute any code this way as this would require a XWiki.ComponentMethodClass with a script macro and for this one the generic required rights analyzer works and triggers warnings when rights are granted. This is created as a security issue mainly to be on the safe side in case on closer analysis we discover an actual security impact.

      Attachments

        Issue Links

          Activity

            People

              MichaelHamann Michael Hamann
              MichaelHamann Michael Hamann
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: