Comment 34 for bug 1677723

Revision history for this message
Boris Bobrov (bbobrov) wrote : Re: federated user gets wrong role (CVE-2017-2673)

Mitaka is not affected. It is impossible to get a project-scoped token skipping the unscoped one, and getting unscoped one fails (there is a test for that).