Project

General

Profile

Actions

Defect #10044

closed

Security bug on Atom feed access

Added by Oguzhan Eren over 13 years ago. Updated over 12 years ago.

Status:
Closed
Priority:
Urgent
Assignee:
-
Category:
Feeds
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Resolution:
Cant reproduce
Affected version:

Description

"http://www.redmine.org/projects/redmine/activity.atom?key=7eebd204d56e0e2fb7244fab3e74bb5510bc0a02&show_messages=1" redmine project atom feed (I can access to forum activities without authorize)

"http://www.redmine.org/projects/secretproject/activity.atom?key=7eebd204d56e0e2fb7244fab3e74bb5510bc0a02&show_messages=1" and I can access a secretproject forum activities without authorize if I found project identifier: secretproject

suggestion to fix: each project must be use different atom key.

Actions

Also available in: Atom PDF