Removed project admin restricted users are not removed at project visibility switch
Package
Tuleap Community Edition
(tuleap)
Affected versions
< 14.9.99.63
Patched versions
14.9.99.63
Tuleap Enterprise Edition
(tuleap)
< 14.10-1
14.10-1
When switching from a project visibility that allows restricted users to
Private without restricted
, restricted users that are project administrators keep this access right.Impact
Restricted users that were project administrators before the visibility switch keep the possibility to access the project and do some administration actions.
Patches
The following versions contain the fix:
For more information
If you have any questions or comments about this advisory, reach out to us via the contact information provided on the Tuleap.org security page.
References