Uploaded image for project: 'Core Server'
  1. Core Server
  2. SERVER-10896

Enforce prohibition of embedded NULLs in role names.

    • Type: Icon: Improvement Improvement
    • Resolution: Done
    • Priority: Icon: Major - P3 Major - P3
    • 3.3.9
    • Affects Version/s: 2.5.2
    • Component/s: Security
    • Labels:
      None
    • Minor Change
    • Security 16 (06/24/16)

      Expected behavior:

      > db.runCommand({createRole: "foo\0er", roles: [], privileges: []})
      { "ok" : 0, ... }
      

      Actual behavior:

      > db.runCommand({createRole: "foo\0er", roles: [], privileges: []})
      { "ok" : 1 }
      > db.getSiblingDB("admin").system.roles.find()
      { "_id" : "test.foo\u0000er", "name" : "foo\u0000er", "source" : "test", "privileges" : [ ], "roles" : [ ] }
      

            Assignee:
            haikinh.hoang@mongodb.com Kinh Hoang
            Reporter:
            schwerin@mongodb.com Andy Schwerin
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: