Elasticsearch not restricting the user search when isolated institutions turned on

Bug #1836984 reported by Robert Lyon
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Mahara
19.04
Fix Released
High
Unassigned
19.10
Fix Released
High
Robert Lyon
20.04
Fix Released
High
Robert Lyon

Bug Description

When I am a member of an institution and the isolated institutions are on and the search has been reindexed I can still see users outside my institution

CVE References

Revision history for this message
Mahara Bot (dev-mahara) wrote : A patch has been submitted for review

Patch for "master" branch: https://reviews.mahara.org/10180

Revision history for this message
Mahara Bot (dev-mahara) wrote :

Patch for "master" branch: https://reviews.mahara.org/10628

information type: Public → Private Security
Revision history for this message
Kristina Hoeppner (kris-hoeppner) wrote :

Vulnerability type: Incorrect access control
Attack type: Remote
Impact: Information disclosure
Affected: Elasticsearch implementation in Mahara

In Mahara 19.04 before 19.04.4 and 19.10 before 19.10.2, account details are shared in the Elasticsearch results for accounts that are not accessible when the config setting 'Isolated institutions' is turned on.

Reference: https://bugs.launchpad.net/mahara/+bug/1836984
Credit: Robert Lyon (Catalyst IT)
CVE: 2020-9387

(link CVE number to https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-9387

Robert Lyon (robertl-9)
Changed in mahara:
milestone: 20.04.0 → none
Robert Lyon (robertl-9)
information type: Private Security → Public Security
Changed in mahara:
status: Fix Committed → Fix Released
no longer affects: mahara
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.