mirror of
https://github.com/silverstripe/silverstripe-framework
synced 2024-10-22 12:05:37 +00:00
[CVE-2019-12617] Fix access escalation for CMS users with limited access through permission cache pollution
This commit is contained in:
parent
eccfa9b10d
commit
8b7063a8e2
@ -752,6 +752,7 @@ class InheritedPermissions implements PermissionChecker, MemberCacheFlusher
|
||||
*/
|
||||
protected function generateCacheKey($type, $memberID)
|
||||
{
|
||||
return "{$type}-{$memberID}";
|
||||
$classKey = str_replace('\\', '-', $this->baseClass);
|
||||
return "{$type}-{$classKey}-{$memberID}";
|
||||
}
|
||||
}
|
||||
|
Loading…
x
Reference in New Issue
Block a user