]> git.ipfire.org Git - thirdparty/bugzilla.git/commit
Bug 711714: (CVE-2011-3667) [SECURITY] The User.offer_account_by_email WebService...
authorFrédéric Buclin <LpSolit@gmail.com>
Wed, 28 Dec 2011 22:11:44 +0000 (23:11 +0100)
committerFrédéric Buclin <LpSolit@gmail.com>
Wed, 28 Dec 2011 22:11:44 +0000 (23:11 +0100)
commit2d792a108434d9ea59ebf75ae09fb69cbab6fb71
tree3da27d1b0158d793d42cf87bb3fd479de558b525
parentf8813fc6a94b4e8e6d5e77009458ed8cb5a856c7
Bug 711714: (CVE-2011-3667) [SECURITY] The User.offer_account_by_email WebService method lets you create new user accounts independently of the value of Bugzilla::Auth::Verify::*::user_can_create_account
r=glob a=LpSolit
Bugzilla/User.pm
Bugzilla/WebService/Constants.pm
Bugzilla/WebService/User.pm
createaccount.cgi
token.cgi