A UVMS user that has only a group 'UVMS Package administration' assigned is able to
- Access to node settings of UVMS
- Create User with admin rights
- Modify the password of the user admin
UVMS 6.10.101, UVC 6.10.101
This a defect of the UVMS application in the handling of the security handling.
This bug is now fixed, and the correction will come with version 6.10.111 and 7.00.21.
Both UVMS Service Packs are expected to be delivered mid of July 2023.
Code change was done to handle package administration logic, giving limited access to user with this role and no security features.
Bug ID: DU_AS-7104
Bug Title: The Role Package Administration is DANGEROUS