Skip to content

Do not allow access to non catalog collections even to admins#25376

Open
luk-kaminski wants to merge 2 commits intomasterfrom
security/do_not_allow_access_to_non_catalog_collections_even_to_admin
Open

Do not allow access to non catalog collections even to admins#25376
luk-kaminski wants to merge 2 commits intomasterfrom
security/do_not_allow_access_to_non_catalog_collections_even_to_admin

Conversation

@luk-kaminski
Copy link
Contributor

@luk-kaminski luk-kaminski commented Mar 19, 2026

Description

/nocl TBD

Motivation and Context

Fixes main problem with https://github.com/Graylog2/graylog2-server/security/advisories/GHSA-29mf-wr3m-2352

How Has This Been Tested?

Screenshots (if appropriate):

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Refactoring (non-breaking change)
  • Breaking change (fix or feature that would cause existing functionality to change)

Checklist:

  • My code follows the code style of this project.
  • My change requires a change to the documentation.
  • I have requested a documentation update.
  • I have read the CONTRIBUTING document.
  • I have added tests to cover my changes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant