Comment 25 for bug 1677723

Revision history for this message
Tim Suter (tsuter) wrote : Re: federated user gets wrong role (CVE-2017-2673)

re: comment#21 and Mitaka being affected

While I haven't come to the conclusion that the bug can be triggered in Mitaka, I'm of the opinion that the function get_roles_for_groups() should still have the same patch as the other affected versions (even without test cases to drop engineering load if need be).

based on:
a) the patch is simple and best practice
b) the function is sensitive
c) we may not have covered all edge cases for deployment scenarios

Maybe I am a little bias considering Mitaka's EOL date