Quantcast
Channel: THWACK: All Content - Orion SDK
Viewing all articles
Browse latest Browse all 2677

Bug that allows user with no NCM access to pull from config archives

$
0
0

We have a local account that is configured in NCM as:  None No access to NCM functionality.

 

We validated no NCM access when invoking ConfigSearch like this:

 

swis.invoke('Cirrus.ConfigArchive', 'ConfigSearch',...)

 

HOWEVER, when doing a swis.query("SELECT ... FROM Cirrus.ConfigArchive"), this user is actually able to view configs.

 

This is an application design flaw, correct? (a security flaw)


Viewing all articles
Browse latest Browse all 2677

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>