Bug 51654 - Do not document vulnerability with which stundent can gain Administrator permissions
Do not document vulnerability with which stundent can gain Administrator perm...
Status: RESOLVED FIXED
Product: UCS
Classification: Unclassified
Component: Self Service
UCS 4.4
Other Linux
: P5 enhancement (vote)
: ---
Assigned To: UMC maintainers
UMC maintainers
:
Depends on: 39952
Blocks:
  Show dependency treegraph
 
Reported: 2020-07-09 11:08 CEST by Florian Best
Modified: 2020-07-16 17:42 CEST (History)
5 users (show)

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: 2: Improvement: Would be a product improvement
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Florian Best univentionstaff 2020-07-09 11:08:07 CEST
The LDAP ACL's suggested in https://wiki.univention.de/index.php/Cool_Solution_-_User_Self-Service_with_extended_Attributes are vulnerable.

With these ACL'S a UCS@school student can make himself a UCS@school Admin.
(Why? See explanation in Bug #39952 comment 12).

Nowerdays, the manual ACL registration is also not necessary as you can simply set UCR variables:
ucr set self-service/ldap_attributes=univentionFreeAttribute1

+++ This bug was initially created as a clone of Bug #39952 +++
Comment 1 Ingo Steuwer univentionstaff 2020-07-16 17:42:44 CEST
The article was for old UCS versions only, I removed it leaving only the link for UCS 4.4 Self Service.