The administrative page, block/add, doesn't check whether or not a user has access to create a bean of a specific type before generating the list.

CommentFileSizeAuthor
#1 bean-permissions-1839966-1.patch1.01 KBultimateboy

Comments

ultimateboy’s picture

Status: Active » Needs review
StatusFileSize
new1.01 KB
indytechcook’s picture

Priority: Normal » Critical
Status: Needs review » Fixed

Thanks! http://drupal.org/commitlog/commit/22232/303c4e7cbcd2a0285a3b965f62221b0...

I'd almost consider this a security issue.

Status: Fixed » Closed (fixed)

Automatically closed -- issue fixed for 2 weeks with no activity.