Page MenuHomePhabricator

L36 Legalpad document is editable by anyone
Closed, ResolvedPublicSecurity


L36 only requires you to be a member of User-JeanFred to edit, which is a publicly join-able project. Having abilities to edit Legalpad documents allows you to see signatures, which could contain real names and emails and which could potentially be considered PII. It also allows you to enable "Signature Required to use Phabricator" which will kick everyone off Phabricator until they sign it. The project should be removed from the access policy.


Risk Rating
Author Affiliation
Wikimedia Communities

Event Timeline

Dylsss renamed this task from Legalpad document is editable by anyone to L36 Legalpad document is editable by anyone.May 10 2022, 1:39 AM
Dylsss updated the task description. (Show Details)
Aklapper claimed this task.
Aklapper added a project: Phabricator.

Uhm... indeed. :( Thanks a lot for catching this; I have fixed it.

sbassett moved this task from Incoming to Our Part Is Done on the Security-Team board.
sbassett subscribed.

@Aklapper - I assume this is fine to make public now?

sbassett triaged this task as Medium priority.May 10 2022, 5:21 PM
sbassett changed Author Affiliation from N/A to Wikimedia Communities.
sbassett changed the visibility from "Custom Policy" to "Public (No Login Required)".
sbassett changed the edit policy from "Custom Policy" to "All Users".
sbassett changed Risk Rating from N/A to Low.