Potential security risk: uploaded pictures accessible #475
Labels
No labels
A: API
A: Backend
A: Federation
A: Front-End
A: I18N
A: Meta
A: Security
Build
C: Bug
C: Discussion
C: Enhancement
C: Feature
Compatibility
Dependency
Design
Documentation
Good first issue
Help welcome
Mobile
Rendering
S: Blocked
S: Duplicate
S: Incomplete
S: Instance specific
S: Invalid
S: Needs Voting/Discussion
S: Ready for review
Suggestion
S: Voted on Loomio
S: Wontfix
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: Plume/Plume#475
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
While being logged in with any account, the user is able to view all pictures uploaded to the website. To reproduce: go to https://fediverse.blog/medias/4620 for example. Just by knowing the 4-digit id of a picture, everybody can see a picture uploaded by any account, no matter if the author decided to publish it or not. A malicious actor could brute-force/guess all ids, granting him access to all pictures on the instance. They would also be able to delete the picture.
Please fix this as fast as possible!
This should have been fixed in #410. @BaptisteGelez is fediverse.blog up to date?
Huuuhh… not very much I think. I will update now.