Details
-
Bug
-
Resolution: Fixed
-
Major
-
15.9-rc-1
-
None
-
Unit
-
Unknown
-
N/A
-
N/A
-
Description
The class XWiki.EventStream.Code.EventClass should have its own required rights analyzer that indicates the required admin right to allow the correct automatic configuration of required rights. This is not a security vulnerability as the two fields that can contain code are already analyzed as Velocity code and thus trigger warnings. I cannot think of any relevant security impact of a XWiki.EventStream.Code.EventClass where those scripts are empty.