You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The vulnerability allows a non-admin user holding only the granular users.edit permission to lock every admin out of the instance by editing the activated flag (which determines whether or not a user can login) and the ldap_import flag, which determines whether or not the user can request a password reset.
Impact
The vulnerability allows a non-admin user holding only the granular
users.editpermission to lock every admin out of the instance by editing theactivatedflag (which determines whether or not a user can login) and theldap_importflag, which determines whether or not the user can request a password reset.Patches
Patched in 403f9c8