Merge branch 'admin-api-revocation' into 'develop'
Admin api revocation fix Closes #3390 See merge request pleroma/pleroma!4382
This commit is contained in:
commit
2980788c8e
3 changed files with 35 additions and 4 deletions
1
changelog.d/admin-self-revocation.security
Normal file
1
changelog.d/admin-self-revocation.security
Normal file
|
|
@ -0,0 +1 @@
|
|||
Admin API: Fixed self-revocation vulnerability where admins could accidentally revoke their own admin status via the single-user permission endpoint
|
||||
Loading…
Add table
Add a link
Reference in a new issue