In certain cases an ordinary user with permission 'View users by role' might get access to view private fields of another user including their email address.

Secondly, a sub-admin user with permission 'Edit users by role' is missing access to view the private fields.

CommentFileSizeAuthor
#2 private-field-access.3054648-2.patch600 bytesadamps

Comments

AdamPS created an issue. See original summary.

adamps’s picture

StatusFileSize
new600 bytes

  • 8325678 committed on 8.x-3.x
    Issue #3054648 by AdamPS: Incorrect access granted to view email...
adamps’s picture

Status: Active » Fixed

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.