The long road to a fix for CVE-2021-20316
The long road to a fix for CVE-2021-20316
Posted Feb 11, 2022 15:17 UTC (Fri) by Paf (subscriber, #91811)Parent article: The long road to a fix for CVE-2021-20316
There doesn’t have to be, or at least not this kind…. Having a separate *path navigation* for security check and for the operation is … wow. You do a security oriented lookup on the entity (in this case the parent), checking permissions as you go, then you have the entity. You then just use it. That the path is processed twice is … loopy and obviously a huge problem.
Posted Feb 11, 2022 15:23 UTC (Fri)
by Paf (subscriber, #91811)
[Link] (1 responses)
Posted Feb 11, 2022 17:45 UTC (Fri)
by jra (subscriber, #55261)
[Link]
The long road to a fix for CVE-2021-20316
The long road to a fix for CVE-2021-20316