Potential security risk: uploaded pictures accessible #475

Closed
opened 2019-03-12 18:45:34 +00:00 by MrSoUndso · 2 comments
MrSoUndso commented 2019-03-12 18:45:34 +00:00 (Migrated from github.com)

While being logged in with any account, the user is able to view all pictures uploaded to the website. To reproduce: go to https://fediverse.blog/medias/4620 for example. Just by knowing the 4-digit id of a picture, everybody can see a picture uploaded by any account, no matter if the author decided to publish it or not. A malicious actor could brute-force/guess all ids, granting him access to all pictures on the instance. They would also be able to delete the picture.

Please fix this as fast as possible!

  • Plume version: 0.2.0
While being logged in with any account, the user is able to view all pictures uploaded to the website. To reproduce: go to https://fediverse.blog/medias/4620 for example. Just by knowing the 4-digit id of a picture, everybody can see a picture uploaded by any account, no matter if the author decided to publish it or not. A malicious actor could brute-force/guess all ids, granting him access to all pictures on the instance. They would also be able to delete the picture. Please fix this as fast as possible! - **Plume version:** 0.2.0

This should have been fixed in #410. @BaptisteGelez is fediverse.blog up to date?

This should have been fixed in #410. @BaptisteGelez is fediverse.blog up to date?
elegaanz commented 2019-03-12 18:55:21 +00:00 (Migrated from github.com)

Huuuhh… not very much I think. I will update now.

Huuuhh… not very much I think. I will update now.
Sign in to join this conversation.
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: Plume/Plume#475
No description provided.