Comment 1 for bug 1677723

Revision history for this message
Boris Bobrov (bbobrov) wrote : Re: federated user gets wrong role

To use this vulnerability, attacker can ask admin get a role in their project (hey admin@Default, could you please have a look at instances in my project?) and get all admin privileges as soon as admin assigns themselves role at attacker's project.