summaryrefslogtreecommitdiffstats
path: root/query.cgi
diff options
context:
space:
mode:
authorjustdave%bugzilla.org <>2004-10-25 16:19:05 +0200
committerjustdave%bugzilla.org <>2004-10-25 16:19:05 +0200
commit23df77be557e495a78808769378ce1f29ac00b4f (patch)
treeb666f7f287d3276f4c50b5bd547a69e7b6a1eda8 /query.cgi
parentb121584e4a4c4dd1ca7ffd1d8cdf51b8a8551a07 (diff)
downloadbugzilla-23df77be557e495a78808769378ce1f29ac00b4f.tar.gz
bugzilla-23df77be557e495a78808769378ce1f29ac00b4f.tar.xz
[SECURITY] Bug 252638: It is possible to send a carefully crafted HTTP POST message to process_bug.cgi which will remove keywords from a bug even if you don't have permissions to edit all bug fields (the "editbugs" permission). Such changes are reported in "bug changed" email notifications, so they are easily detected and reversed if someone abuses it.
Patch by Myk Melez <myk@mozilla.org> r=gerv, a=justdave
Diffstat (limited to 'query.cgi')
0 files changed, 0 insertions, 0 deletions