View Issue Details

IDProjectCategoryView StatusLast Update
0017669mantisbtsecuritypublic2014-12-14 16:19
Reporteratrol Assigned Tovboctor  
PriorityhighSeveritymajorReproducibilityhave not tried
Status closedResolutionduplicate 
Product Version1.2.17 
Fixed in Version1.2.18 
Summary0017669: Reporters are able to assign issues
Description

Users with access level reporter are able to assign issues.
Example at #17668

I have no time for a deeper look at the moment.
Just a speculation that it might be caused by the SOAP API.

TagsNo tags attached.

Relationships

duplicate of 0016993 closedvboctor Handler can be set without having appropriate access rights 
related to 0009885 closedvboctor Emails on relations is send to people who cannot see the related issue 
related to 0017878 closeddregad Prevent unauthorized users setting handler when reporting issue 

Activities

atrol

atrol

2014-09-16 11:07

developer   ~0041228

Just noticed that I reported the same some time ago, see 0016993
Unfortunately I didn't set the view status to private.

I don't want to set any relationship for it or touch it as there is also 0009885