Staff can edit other staff using the user buckets bypassing permission checks
Bug #2020196 reported by
Steve Callender
This bug affects 6 people
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Evergreen |
Confirmed
|
High
|
Unassigned |
Bug Description
Tested in EG 3.9.2
Staff members that do not have permission to edit users in certain permission groups can bypass the permission blocks by adding a staff member to a bucket and doing a batch edit.
I tested with a staff account editing another account they do not have permission to edit. In the patron editor it's blocked with the message "Editing users in this group is disallowed". However, putting that user in a bucket allows me to change the individual account settings that are part of the batch edit process, such as home library, or profile that would allow me to move that user into a permission group that I CAN fully edit.
information type: | Public → Public Security |
Changed in evergreen: | |
importance: | Undecided → High |
status: | New → Confirmed |
tags: | added: buckets-user permissions |
To post a comment you must log in.
Update, I cannot edit the permission group this way, but I can edit the home library and everything else, but the permission group/profile still successfully blocks and requires an override.