Actions
Defect #31778
closedTotal estimated time issue query column and issue field might leak information
Start date:
Due date:
% Done:
0%
Estimated time:
Resolution:
Affected version:
Description
The total estimated time information will show the sum of the estimated times of the issues and its subissues. This calculation does not verify if the current user is allowed to see the sub issues though, which might lead to an information leak.
Attached is a patch with a test for this issue. This patch was created and contributed by Gregor Schmidt.
Files
Related issues
Actions