Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[WFCORE-6544] CVE-2023-4061 Management RBAC permission allows unexpected reading of system-properties via resolve-expression #5703

Merged
merged 3 commits into from
Oct 6, 2023

Conversation

bstansberry
Copy link
Contributor

@bstansberry
Copy link
Contributor Author

@darranl Please review

@github-actions github-actions bot added the deps-ok Dependencies have been checked, and there are no significant changes label Oct 5, 2023
@yersan yersan requested a review from darranl October 6, 2023 09:36
@@ -0,0 +1,109 @@
package org.jboss.as.test.integration.mgmt.access;
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We should add a license header later, it is not a hard requirement.

@bstansberry bstansberry merged commit 25728f3 into wildfly:main Oct 6, 2023
1 check passed
@bstansberry bstansberry deleted the WFCORE-6544 branch October 6, 2023 13:19
@bstansberry
Copy link
Contributor Author

Thanks @yersan. Right before merging I added a commit to add the license header.

Copy link
Contributor

@darranl darranl left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Blocker deps-ok Dependencies have been checked, and there are no significant changes
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants