Uploaded image for project: 'MariaDB MaxScale'
  1. MariaDB MaxScale
  2. MXS-6579

X-HTTP-Method-Override header allows a basic user to perform admin operations

    XMLWordPrintable

Details

    Description

      Essentially allows a read-only REST-API user to perform write-operations. Authentication is still required.

      This issue applies to MaxScale 25.10 only partially, as 25.10 authorizes against the effective HTTP method and not the "fake" one. 25.10 still uses the wrong method in some checks, e.g. it can be fooled to compare against admin_readonly_hosts when admin_readwrite_hosts would be correct.

      Attachments

        Activity

          People

            esa.korhonen Esa Korhonen
            esa.korhonen Esa Korhonen
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Time Tracking

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Remaining Estimate - 0d
                0d
                Logged:
                Time Spent - 2d
                2d

                Git Integration

                  Error rendering 'com.xiplink.jira.git.jira_git_plugin:git-issue-webpanel'. Please contact your Jira administrators.