Description
In Internet2 Grouper 5.17.1 before 5.20.5, group admins who are not Grouper sysadmins can configure loader jobs.
Problem types
CWE-863 Incorrect Authorization
Product status
5.17.1 (semver) before 5.20.5
References
spaces.at.internet2.edu/...-admins+can+configure+loader+jobs
spaces.at.internet2.edu/...-admins+can+configure+loader+jobs