Project

General

Custom queries



Profile

Actions

Defect #10390

closed

Mass assignment security vulnerability

Added by John Yani about 13 years ago. Updated about 13 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Category:
Code cleanup/refactoring
Target version:
Start date:
Due date:
% Done:

0%

Estimated time:
Resolution:
Fixed
Affected version:

Description

There are many security vulnerabilities in Redmine. Some are not dangerous (such as setting created_on and updated_on fields). Some are (posting news to the project you're not allowed to).

#3

Updated by Jean-Philippe Lang about 13 years ago

  • Category set to Code cleanup/refactoring
  • Status changed from New to Closed
  • Target version set to 1.3.2
  • Resolution set to Fixed
Actions

Also available in: Atom PDF