diff options
author | justdave%bugzilla.org <> | 2004-10-25 16:19:05 +0200 |
---|---|---|
committer | justdave%bugzilla.org <> | 2004-10-25 16:19:05 +0200 |
commit | 23df77be557e495a78808769378ce1f29ac00b4f (patch) | |
tree | b666f7f287d3276f4c50b5bd547a69e7b6a1eda8 /editgroups.cgi | |
parent | b121584e4a4c4dd1ca7ffd1d8cdf51b8a8551a07 (diff) | |
download | bugzilla-23df77be557e495a78808769378ce1f29ac00b4f.tar.gz bugzilla-23df77be557e495a78808769378ce1f29ac00b4f.tar.xz |
[SECURITY] Bug 252638: It is possible to send a carefully crafted HTTP POST message to process_bug.cgi which will remove keywords from a bug even if you don't have permissions to edit all bug fields (the "editbugs" permission). Such changes are reported in "bug changed" email notifications, so they are easily detected and reversed if someone abuses it.
Patch by Myk Melez <myk@mozilla.org>
r=gerv, a=justdave
Diffstat (limited to 'editgroups.cgi')
0 files changed, 0 insertions, 0 deletions