Previous password required in account preferences, not user editing pages

Bug #1298787 reported by Julian Edwards
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
MAAS
Won't Fix
Medium
Unassigned

Bug Description

Users with MAAS admin privileges are able to modify and delete user accounts using URLs such as
/MAAS/accounts/root/edit/. Similar changes to account details can be made via the account details
page at /MAAS/account/prefs/; however, changing a password via this page requires the user’s
existing password to be entered, whereas changing it via the former user does not.

Tags: netcraft
Changed in maas:
status: Triaged → Won't Fix
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.