mirror of
https://github.com/silverstripe/silverstripe-framework
synced 2024-10-22 12:05:37 +00:00
[CVE-2019-12617] Fix access escalation for CMS users with limited access through permission cache pollution
This commit is contained in:
parent
eccfa9b10d
commit
8b7063a8e2
@ -752,6 +752,7 @@ class InheritedPermissions implements PermissionChecker, MemberCacheFlusher
|
|||||||
*/
|
*/
|
||||||
protected function generateCacheKey($type, $memberID)
|
protected function generateCacheKey($type, $memberID)
|
||||||
{
|
{
|
||||||
return "{$type}-{$memberID}";
|
$classKey = str_replace('\\', '-', $this->baseClass);
|
||||||
|
return "{$type}-{$classKey}-{$memberID}";
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
Loading…
x
Reference in New Issue
Block a user