• justdave%bugzilla.org's avatar
    [SECURITY] Bug 263780: Exporting a bug to XML exposes user comments and… · 53bd4df6
    justdave%bugzilla.org authored
    [SECURITY] Bug 263780: Exporting a bug to XML exposes user comments and attachment summaries which are marked as private to users who are not members of the group allowed to see private comments and attachments.  XML export is not exposed in the user interface, but is available to anyone who knows the correct URL to invoke it.  This only affects sites that use the 'insidergroup' feature.
    Patch by Joel Peshkin <bugreport@peshkin.net>
    r=vladd,justdave, a=justdave
    53bd4df6
Name
Last commit
Last update
..
account Loading commit data...
admin Loading commit data...
attachment Loading commit data...
bug Loading commit data...
flag Loading commit data...
global Loading commit data...
list Loading commit data...
pages Loading commit data...
reports Loading commit data...
request Loading commit data...
search Loading commit data...
whine Loading commit data...
config.js.tmpl Loading commit data...
config.rdf.tmpl Loading commit data...
filterexceptions.pl Loading commit data...
index.html.tmpl Loading commit data...
sidebar.xul.tmpl Loading commit data...