elastic / kibana

Your window into the Elastic Stack
https://www.elastic.co/products/kibana
Other
19.82k stars 8.2k forks source link

[Security Solution]Security Privilege access conflicting between Read and None #126335

Open ghost opened 2 years ago

ghost commented 2 years ago

Describe the bug Security Privilege access conflicting between Read and None

Build Details

Version: 8.1.0-BC3
Commit:0335dd6a26ef29ae9021d0fae9347dc88f3b7d6e
Build:50346

Pre-Condition

Role 2
 - Security : None
 - Case : All

Steps

we came up with below suggestion for this issue:-

image

image

Observations:

Please find below actual observation for different page of security app on setting security feature to Read and None under kibana privilege

Security Privilege Overview Alerts Rules Exception Host Network Timeline Cases Mange Group
Security : Read , Case : All All Access ❌ Read Access ✔️ Read Access ✔️ Read Access ✔️ All Access ❌ All Access ❌ All Access ❌ All Access ✔️ Out of Scope as this page requires only super user to access them
Security : None, Case : All No Access ✔️ No Access ✔️ No Access ✔️ No Access ✔️ No Access ✔️ No Access ✔️ No Access ✔️ Access ✔️ Out of Scope as this page requires only super user to access them

Screen-Cast

https://user-images.githubusercontent.com/59917825/155517129-731a478b-e331-46a2-983b-9dba3bbe958a.mp4

https://user-images.githubusercontent.com/59917825/155517114-330e9a0a-e859-41ff-a08f-73242d64a0a0.mp4

elasticmachine commented 2 years ago

Pinging @elastic/security-solution (Team: SecuritySolution)

manishgupta-qasource commented 2 years ago

Reviewed & assigned to @MadameSheema

elasticmachine commented 2 years ago

Pinging @elastic/security-detections-response (Team:Detections and Resp)

yctercero commented 2 years ago

@XavierM Hey Xavier! I might be remembering wrong, but I thought I saw you had a PR or issue around this?