Impact
All authenticated users can access the roles and permissions screen and add/change/remove any permission regardless of their permissions. Permission changes via rest are also possible form any authenticated user.
A security interceptor was not working which disabled the security checks for permission changes completely.
Patches
This issue has been fixed in version 1.17.36. It's unclear in which version this interceptor stopped working.
Impact
All authenticated users can access the roles and permissions screen and add/change/remove any permission regardless of their permissions. Permission changes via rest are also possible form any authenticated user.
A security interceptor was not working which disabled the security checks for permission changes completely.
Patches
This issue has been fixed in version 1.17.36. It's unclear in which version this interceptor stopped working.