Uploaded image for project: 'Infinispan'
  1. Infinispan
  2. ISPN-9599

DefaultCacheManager.getGlobalComponentRegistry should require ADMIN permission

    XMLWordPrintable

Details

    • Bug
    • Resolution: Done
    • Major
    • 10.0.0.Final, 9.4.17.Final
    • 9.3.3.Final, 9.4.0.Final
    • Core
    • None

    Description

      DefaultCacheManager.getGlobalComponentRegistry() allows invoking any component without additional permission checks, so it needs ADMIN permission.
      DefaultCacheManager.getCacheManagerConfiguration() also allows access to some internal components, so it also needs ADMIN permission.

      Attachments

        Activity

          People

            dberinde@redhat.com Dan Berindei (Inactive)
            dberinde@redhat.com Dan Berindei (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: