Comment 33 for bug 1677723

Revision history for this message
Boris Bobrov (bbobrov) wrote : Re: federated user gets wrong role (CVE-2017-2673)

Mitaka is probably affected too, if someone directly gets a project-scoped federated token, but i cannot verify that because of lack of environment. The fix should be the same, but the unit test needs to be heavily changed. I will do my best to write them soon, but feel free to do it if you need it sooner.