Skip to:
Content

bbPress.org

Opened 7 years ago

Closed 7 years ago

Last modified 6 years ago

#2334 closed defect (fixed)

Linking security issue/Private topics surface

Reported by: caming Owned by:
Milestone: 2.4 Priority: high
Severity: major Version: 2.1
Component: Component - Search Keywords:
Cc:

Description

Upgraded to 2.3, and when a casual user chooses to hyperlink and opts to “Use Existing Content” and performs a search, all topic subjects posted in a Private forum (in this case, our moderator forum) are presented.

From JJJ: Sigh. No; first I’ve heard of it, and totally lame that’s happening.

Change History (3)

#1 @jaredatch
7 years ago

I actually discovered this a month ago and posted about it in the (now removed, I beleive) Staff forums on bbPress.org. No one really read that and I just kinda forgot about it, sorry about that.

At the time I believe I was able to replicate this, so it's certainly something we want to look into and get fixed as quick as possible.

Thanks for reporting.

#2 @johnjamesjacoby
7 years ago

  • Component changed from Users to Search
  • Milestone changed from Awaiting Review to 2.4
  • Resolution set to fixed
  • Status changed from new to closed

Fixed as part of #2337.

#3 @johnjamesjacoby
6 years ago

In 5006:

Make sure that topics and replies in private/hidden forums are excluded from the "insert links" dialogue window. Hat tip jaredatch. See #2334.

Note: See TracTickets for help on using tickets.