Uploaded image for project: 'Observium'
  1. Observium
  2. OBS-913

Users can access information about devices they don't have permission for.

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • Major
    • None
    • None
    • Web Interface
    • We run Observium CE version 0.14.4.5185

    Description

      Account "user1", with access level "Normal User" has configured access to device "server1". That server shares network segment with some other servers and for example "router1"

      When user1 go to see his server's port status, in the Details page, he will find all the others servers information like:

      • names used in observium,
      • interfaces names, like Eth0
      • IP addresses (in this shared segment)
      • name, port name/number on the router1

      Even the labels are not links, and user1 can't go further accessing more information about other devices, I don't think that information must be available to him.

      I file this bug, because that prevents me to give my client access to the monitoring.

      Link to the mailing list: http://postman.memetic.org/pipermail/observium/2014-July/007197.html

      Best Regards!

      Attachments

        Activity

          People

            sid3windr Tom Laermans
            yavor Yavor Buyukliev
            Votes:
            3 Vote for this issue
            Watchers:
            6 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: