From e39ea822a5dec23ea34c7784337247b18946a881 Mon Sep 17 00:00:00 2001 From: "lpsolit%gmail.com" <> Date: Sun, 3 Jun 2007 14:21:55 +0000 Subject: Bug 382974: $duplicate can be set even when not marking a bug as a dupe (security check bypass) - Patch by Frédéric Buclin r=justdave a=LpSolit MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- process_bug.cgi | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'process_bug.cgi') diff --git a/process_bug.cgi b/process_bug.cgi index bb0d608a5..170fb87a5 100755 --- a/process_bug.cgi +++ b/process_bug.cgi @@ -951,7 +951,7 @@ $vars->{resolution} = $cgi->param('resolution') || ''; Bugzilla::Bug->check_status_change_triggers($knob, \@idlist, $vars); # Some triggers require extra actions. -$duplicate = $vars->{dup_id}; +$duplicate = $vars->{dup_id} if ($knob eq 'duplicate'); $requiremilestone = $vars->{requiremilestone}; DuplicateUserConfirm($vars->{bug_id}, $duplicate) if $vars->{DuplicateUserConfirm}; _remove_remaining_time() if $vars->{remove_remaining_time}; -- cgit v1.2.3-24-g4f1b