]> git.ipfire.org Git - thirdparty/bugzilla.git/commit
[SECURITY] Bug 252638: It is possible to send a carefully crafted HTTP POST message...
authorjustdave%bugzilla.org <>
Mon, 25 Oct 2004 14:20:59 +0000 (14:20 +0000)
committerjustdave%bugzilla.org <>
Mon, 25 Oct 2004 14:20:59 +0000 (14:20 +0000)
commit5caab2d83315c58ad7c8c716448d2462c6397da4
treedb3ba54a89b0d5a011a04133b0e075e9c031a6a7
parent814bb4e9c8b0028ea988a382f5559218b7f4e3f8
[SECURITY] Bug 252638: It is possible to send a carefully crafted HTTP POST message to process_bug.cgi which will remove keywords from a bug even if you don't have permissions to edit all bug fields (the "editbugs" permission).  Such changes are reported in "bug changed" email notifications, so they are easily detected and reversed if someone abuses it.
Patch by Myk Melez <myk@mozilla.org>
r=gerv, a=justdave
process_bug.cgi