|
php.net | support | documentation | report a bug | advanced search | search howto | statistics | random bug | login |
Patchesbugsweb-security.diff (last revision 2012-05-07 20:59 UTC by tyrael@php.net)Pull RequestsHistoryAllCommentsChangesGit/SVN commits
[2012-05-05 18:35 UTC] tyrael@php.net
[2012-05-05 20:25 UTC] tyrael@php.net
[2012-05-05 20:26 UTC] tyrael@php.net
[2012-05-05 20:28 UTC] tyrael@php.net
[2012-05-05 21:01 UTC] pajoye@php.net
[2012-05-05 21:11 UTC] tyrael@php.net
[2012-05-05 21:44 UTC] tyrael@php.net
-Status: Open
+Status: Assigned
-Assigned To:
+Assigned To: tyrael
[2012-05-06 19:03 UTC] tyrael@php.net
[2012-05-06 19:08 UTC] tyrael@php.net
[2012-05-07 20:59 UTC] tyrael@php.net
[2012-05-08 23:36 UTC] tyrael@php.net
-Status: Assigned
+Status: Closed
[2012-05-08 23:36 UTC] tyrael@php.net
|
|||||||||||||||||||||||||||
Copyright © 2001-2025 The PHP GroupAll rights reserved. |
Last updated: Sat Nov 08 17:00:02 2025 UTC |
Description: ------------ I just reported a few security issues, and noticed that: - anybody can access the basic information about the private/security bugs (summary, Submitted, Modified, From, Assigned, Status, Package, PHP version, OS, CVE-ID). - logged in users can't access the bug, they are still asked for a password, which they don't have, as they didn't had to provide that at the original report. - I'm not sure that it is a bug, or just a mail delivery issue, but when I tried to recover the password through the bug-pwd-finder.php, it said it was successful ("The password for bug report #60988 has been sent to tyrael@php.net"), but I didn't get any mail.