| | 100 | After review, we've determined that the reported issue concerns a feature that does not implement per-object permission checks. Since this missing feature is transparent to site administrators, we find it unlikely that an attacker could exploit this knowledge over them. Finally, per-object permissions are hooks for application logic rather than mechanisms to prevent permission escalation worries for entire groups. Thus, we prefer to develop fixes and features in this area via the public development process. |