• Drew Blessing's avatar
    Prevent double-impersonation and impersonation breakout · 780c8592
    Drew Blessing authored
    When an admin impersonated another admin, it was possible to
    impersonate multiple levels deep. The side-effect is when
    stopping impersonation at a deeper level the actual user
    would then assume the session of the last impersonating user
    rather than their own session.
    
    Changelog: security
    780c8592
gitlab.pot 892 KB