View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
09219 | Bug reports | Security | public | 2014-09-08 21:35 | 2015-01-03 19:50 |
Reporter | sykano | Assigned To | mdekker | ||
Priority | normal | Severity | partial_block | ||
Status | closed | Resolution | duplicate | ||
Product Version | 2.05+ | ||||
Summary | 09219: blocked LDAP users can use "forgot password" to login locally -> security issue | ||||
Description | Since LDAP users are internally normal user accounts in Limesurvey, a user whose account is blocked in the central AD can manage to login by getting a password for the local login via the "forgot password" function. This is a security issue! It can undermine company security policies! Also, note that local login can't be deactivated. But that wouldn't be enough to fix the issue, sometimes you might need the local login. | ||||
Steps To Reproduce |
| ||||
Additional Information | I suggest to internally distinguish user accounts that are LDAP user accounts from normal local user accounts. As a side note I also like to suggest to make it possible to deactivate the local login. | ||||
Tags | No tags attached. | ||||
Bug heat | 250 | ||||
Complete LimeSurvey version number (& build) | buidl 20140703 | ||||
I will donate to the project if issue is resolved | No | ||||
Browser | Firefox, Chrome | ||||
Database type & version | mysql 5.1.73 | ||||
Server OS (if known) | Linux (CentOS 6.5) | ||||
Webserver software & version (if known) | apache 2.2.15 | ||||
PHP Version | 5.3.3 | ||||
Date Modified | Username | Field | Change |
---|---|---|---|
2014-09-08 21:35 | sykano | New Issue | |
2014-09-09 12:12 | DenisChenu | Relationship added | duplicate of 08865 |
2014-09-09 12:12 | DenisChenu | Status | new => closed |
2014-09-09 12:12 | DenisChenu | Assigned To | => mdekker |
2014-09-09 12:12 | DenisChenu | Resolution | open => duplicate |