Comment 32 for bug 1324592

Revision history for this message
Tristan Cacqueray (tristan-cacqueray) wrote : Re: Trust scope can be circumvented by chaining trusts

@Morgan,

Thank, that is very helpful, I'll update the impact description.
Just to be sure, the privilege elevation can only happen with out-of-scope roles from the former authentication.
I mean, it's not to any role right ?

@Garth

I would prefer having the impact description validated before requesting a CVE. Then yes, feel free to assign the CVE thanks!