Page MenuHomePhabricator

Special:DeletedContributions leaks IPs if IP is blocked
Closed, ResolvedPublic

Description

If the IP is autoblocked, an indication will appear where it says "Change block" but the IP is not directly blocked. The Special:Contributions issue was fixed with https://phabricator.wikimedia.org/T48457.


patch:

  • 1.25 - same as master ()
  • 1.24 - same as master ()
  • 1.23 - same as master ()

affected versions:
type: info leak

Event Timeline

Maniphest changed the visibility from "Public (No Login Required)" to "Custom Policy".Jul 24 2015, 9:13 PM
Maniphest changed the edit policy from "All Users" to "Custom Policy".
Bsadowski1 triaged this task as Medium priority.
Bsadowski1 updated the task description. (Show Details)
Bsadowski1 added a project: acl*security.
Bsadowski1 changed Security from None to Software security bug.
Bsadowski1 edited subscribers, added: Bsadowski1; removed: Aklapper.
Legoktm subscribed.

This was noted in T48457#531937, but I missed that.

Looks good to me

this is now deployed on wmf16 and wmf17

csteipp added a parent task: Restricted Task.
csteipp changed the visibility from "Custom Policy" to "Public (No Login Required)".Aug 10 2015, 9:59 PM
csteipp changed the edit policy from "Custom Policy" to "All Users".
csteipp changed Security from Software security bug to None.

Change 230667 had a related patch set uploaded (by Chad):
SECURITY: Don't disclose if an IP is autoblocked on Special:DeletedContributions

https://gerrit.wikimedia.org/r/230667

Change 230671 had a related patch set uploaded (by Chad):
SECURITY: Don't disclose if an IP is autoblocked on Special:DeletedContributions

https://gerrit.wikimedia.org/r/230671

Change 230675 had a related patch set uploaded (by Chad):
SECURITY: Don't disclose if an IP is autoblocked on Special:DeletedContributions

https://gerrit.wikimedia.org/r/230675

Change 230675 merged by jenkins-bot:
SECURITY: Don't disclose if an IP is autoblocked on Special:DeletedContributions

https://gerrit.wikimedia.org/r/230675

Change 230671 merged by jenkins-bot:
SECURITY: Don't disclose if an IP is autoblocked on Special:DeletedContributions

https://gerrit.wikimedia.org/r/230671

Change 230667 merged by jenkins-bot:
SECURITY: Don't disclose if an IP is autoblocked on Special:DeletedContributions

https://gerrit.wikimedia.org/r/230667

Change 230776 had a related patch set uploaded (by Chad):
SECURITY: Don't disclose if an IP is autoblocked on Special:DeletedContributions

https://gerrit.wikimedia.org/r/230776

Change 230776 merged by jenkins-bot:
SECURITY: Don't disclose if an IP is autoblocked on Special:DeletedContributions

https://gerrit.wikimedia.org/r/230776

CVE-2015-6727 was assigned for this.