Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Dont leak private users via extensions (#28023) #28028

Merged
merged 1 commit into from
Nov 13, 2023

Conversation

GiteaBot
Copy link
Collaborator

Backport #28023 by @6543

there was no check in place if a user could see a other user, if you append e.g. .rss

@GiteaBot GiteaBot added topic/security Something leaks user information or is otherwise vulnerable. Should be fixed! type/bug labels Nov 13, 2023
@GiteaBot GiteaBot added this to the 1.20.6 milestone Nov 13, 2023
@GiteaBot GiteaBot added the lgtm/need 2 This PR needs two approvals by maintainers to be considered for merging. label Nov 13, 2023
@GiteaBot GiteaBot requested review from delvh and denyskon November 13, 2023 22:30
@pull-request-size pull-request-size bot added the size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. label Nov 13, 2023
@GiteaBot GiteaBot added lgtm/need 1 This PR needs approval from one additional maintainer to be merged. and removed lgtm/need 2 This PR needs two approvals by maintainers to be considered for merging. labels Nov 13, 2023
@GiteaBot GiteaBot added lgtm/done This PR has enough approvals to get merged. There are no important open reservations anymore. and removed lgtm/need 1 This PR needs approval from one additional maintainer to be merged. labels Nov 13, 2023
@6543 6543 merged commit 69ea554 into go-gitea:release/v1.20 Nov 13, 2023
@go-gitea go-gitea locked as resolved and limited conversation to collaborators Feb 12, 2024
# for free to subscribe to this conversation on GitHub. Already have an account? #.
Labels
lgtm/done This PR has enough approvals to get merged. There are no important open reservations anymore. size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. topic/security Something leaks user information or is otherwise vulnerable. Should be fixed! type/bug
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants