[zanata-bugs] [Bug 1103055] User email addresses can be retrieved through the REST interface without authentication

bugzilla at redhat.com bugzilla at redhat.com
Thu Aug 28 01:50:30 UTC 2014


https://bugzilla.redhat.com/show_bug.cgi?id=1103055

Damian Jansen <djansen at redhat.com> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
             Status|NEW                         |ASSIGNED
           Assignee|djansen at redhat.com          |pahuang at redhat.com



--- Comment #2 from Damian Jansen <djansen at redhat.com> ---
Still a problem.  User emails should _never_ be divulged to other users,
without permission.
This also enabled scraping for malicious intent.

-- 
You are receiving this mail because:
You are on the CC list for the bug.
Unsubscribe from this bug https://bugzilla.redhat.com/token.cgi?t=RSKZMOBf8z&a=cc_unsubscribe




More information about the zanata-bugs mailing list