Uploaded image for project: 'Core Server'
  1. Core Server
  2. SERVER-74292

Reject commands containing both legacy and new impersonated user metadata fields

    • Type: Icon: Task Task
    • Resolution: Fixed
    • Priority: Icon: Major - P3 Major - P3
    • 7.0.0-rc0, 6.3.0-rc3
    • Affects Version/s: None
    • Component/s: None
    • None
    • Fully Compatible
    • v6.3
    • Security 2023-03-06
    • 106

      SERVER-64029 prohibited impersonation of multiple users by introducing a new field for impersonated usernames while retaining backwards compatibility for the legacy version of the field. We should properly enforce that at most only one of these fields is ever present.

            Assignee:
            varun.ravichandran@mongodb.com Varun Ravichandran
            Reporter:
            varun.ravichandran@mongodb.com Varun Ravichandran
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: