Defect #10390
closed
Mass assignment security vulnerability
Added by John Yani about 14 years ago.
Updated about 14 years ago.
Category:
Code cleanup/refactoring
Description
There are many security vulnerabilities in Redmine. Some are not dangerous (such as setting created_on and updated_on fields). Some are (posting news to the project you're not allowed to).
All actions for non-admin users should now be fixed.
- Category set to Code cleanup/refactoring
- Status changed from New to Closed
- Target version set to 1.3.2
- Resolution set to Fixed
Please next time submit security issues to security at redmine dot org as requested on SubmittingBugs.
Also available in: Atom
PDF