Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Secuirty Issue with GetRolesByUser function (DNN 4.3.3/3.3.3)Secuirty Issue with GetRolesByUser function (DNN 4.3.3/3.3.3)
Previous
 
Next
New Post
7/24/2006 11:06 PM
 

 

You are right hmnguyen. 

If it is core security or module security,  it is still a method exposed by the DotNetNuke framework API and there is no reason why a developer should not expect it to return the proper roles for the current user, even if they are not authenticated.

I'm hoping we can get this corrected as soon as possible.


DotNetNuke Modules from Snapsis.com
 
New Post
7/25/2006 2:51 PM
 

Jon - glad to hear, is there a way we can get some official notification of this - I think that module developers should do a quick review of their code to insure that they are not using the function in a way that could comprimise security, and the only way we're going to know about it, is via a bulletin - that's been an established API call for a long time, and you just never know the context in which it's going to be used in.

If I wasn't distracted today and went looking through the forums to find out if someone reported something else in regards to 3.3.3/4.3.3 - I know I would have blithly been ignorant of this issue, which could have caused issues - luckily, I'm just changing one function to make sure the door is slammed shut on this one.

Richard
DNN Modules

 

 
New Post
7/25/2006 3:27 PM
 

 

A notification and a hot-fix is my recommendation but it is not my call.

Please address these issues to security@dotnetnuke.com


DotNetNuke Modules from Snapsis.com
 
New Post
7/27/2006 12:47 PM
 

I sent an email with this thread to security@dotnetnuke.com just in case everyone thought everyone else was going to do it :)

I hope that we'll see some notification so that other third party developers can validate the proper operation of thier code considering that this issue is out there and third party modules are running under it already.

 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Secuirty Issue with GetRolesByUser function (DNN 4.3.3/3.3.3)Secuirty Issue with GetRolesByUser function (DNN 4.3.3/3.3.3)


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out