Page MenuHomePhabricator

Unintentional log-in as foreign user
Closed, ResolvedPublic

Description

Author: peter

Description:
Without logging in, after a reload, I found myself logged in as a foreign user
(unknown to me). I consider this a security hole.


Version: unspecified
Severity: critical
URL: http://de.wikipedia.org

Details

Reference
bz6969

Event Timeline

bzimport raised the priority of this task from to Medium.Nov 21 2014, 9:20 PM
bzimport set Reference to bz6969.
bzimport added a subscriber: Unknown Object (MLST).

Please provide some more information on how this happened. Especially: Do others
have access to your computer? Where you using an HTTP proxy?

Also: did you just see a page with anotehr user's name on it, or where you
actually able to edit using the identity of this user? When navigating the wiki
at random, do you stay logged in as "the other user"?

In case this happens again, please record the following, if you can: the IP
address you got for the wiki site, the HTML page itself, the HTTP response
headers and any cookies you have for the wiki's site.

I'm settings this to "critical" in case it is actually a MediaWiki bug. I
suspect however either a problem with PHP's session handling, a broken proxy, or
a compromized user PC.

[[hu:User:Vince]] reported the same on huwiki a couple of hours ago. The links
to the preferences and watchlist were missing from the personal toolbar,
everything else was there. He remained logged in as another user after following
a link. I'll try to get more details.

ayg wrote:

*** This bug has been marked as a duplicate of 6464 ***