Bug 1394335

Summary: API allows fetching virtual_templates without appropriate role
Product: Red Hat CloudForms Management Engine Reporter: Satoe Imaishi <simaishi>
Component: APIAssignee: abellott
Status: CLOSED ERRATA QA Contact: Martin Kourim <mkourim>
Severity: high Docs Contact:
Priority: high    
Version: 5.7.0CC: cpelland, dajohnso, jhardy, obarenbo, slukasik
Target Milestone: GA   
Target Release: 5.7.0   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: rest:template:security
Fixed In Version: 5.7.0.11 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: 1392612 Environment:
Last Closed: 2017-01-04 13:12:47 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Bug Depends On: 1392612    
Bug Blocks:    

Comment 2 Šimon Lukašík 2016-11-14 15:40:58 UTC
$ git log -1
commit b5eb7caa29c3659a6888de36946c4b01a77adb73
Author: Gregg Tanzillo <gtanzill>
Date:   Thu Nov 10 10:21:57 2016 -0500

Comment 3 Martin Kourim 2016-11-21 18:51:01 UTC
Verified by following steps outlined in the bug description.

Result:
{
  "error": {
    "kind": "forbidden",
    "message": "Use of the read action is forbidden",
    "klass": "Api::ForbiddenError"
  }
}

Status:
403

Comment 5 errata-xmlrpc 2017-01-04 13:12:47 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHBA-2017-0012.html