Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Adding clarification that sub-admin roles should not be able to change their own privileges #1451

Merged

Conversation

renetapopova
Copy link
Contributor

Cherry-picked from #1440

This was noticed in a recent internal pentest of RBAC.

We need to clarify that it is necessary to explicitly deny the ability to change your own privileges if you copy the admin role (otherwise the new role is essentially unconstrained).

…e their own privileges (neo4j#1440)

This was noticed in a recent internal pentest of RBAC.

We need to clarify that it is necessary to explicitly deny the ability
to change your own privileges if you copy the admin role (otherwise the
new role is essentially unconstrained).
@renetapopova renetapopova merged commit cf59ce3 into neo4j:4.4 Feb 28, 2024
@renetapopova renetapopova deleted the 4.4-admin-privileges-clarification branch February 28, 2024 11:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants