Closed Bug 131695 Opened 23 years ago Closed 21 years ago

Leak of secured information when marking bugs as duplicate

Categories

(Bugzilla :: Email Notifications, defect)

2.14.1
defect
Not set
minor

Tracking

()

RESOLVED DUPLICATE of bug 93508

People

(Reporter: thomas.thurman, Assigned: preed)

Details

In our Bugzilla installation, we had a bug "A" that was only visible internally. It was later found that it was a duplicate of "B", which was visible to clients. When "A" was marked as a duplicate, the client was emailed notification that "B" was a duplicate, despite not being able to see "B". Shouldn't there be some way of preventing this? I realise that this is quite a rare case, since duplicate bugs usually have the same visibility, but in some cases there's information in the comments or description which is confidential to one group or another.
Sorry. Let's try that first paragraph again. In our Bugzilla installation, we had a bug "A" that was only visible internally. It was later found that it was a duplicate of "B", which was visible to clients. When "A" was marked as a duplicate, the client was emailed notification that "A" was a duplicate of "B", despite not being able to see "A".
This may be dependent on bug 7415 ("Allow private comments to bugs. ...").
Changing default owner of Email Notifications component to JayPee, a.k.a. J. Paul Reed (preed@sigkill.com). Jake will be offline for a few months.
Assignee: jake → preed
Private comments would definitely be a nice solution here. In the meantime, perhaps a warning should be issued mentioning the fact it doen't have the same groupset.
Target Milestone: --- → Bugzilla 2.18
Dupe of bug 93508?
All 2.18 bugs that haven't been touched in over 60 days and aren't flagged as blockers are getting pushed out to 2.20
Target Milestone: Bugzilla 2.18 → Bugzilla 2.20
Summary: Users should not be told about bugs they can't see → Leak of secured information when marking as duplicate
Summary: Leak of secured information when marking as duplicate → Leak of secured information when marking bugs as duplicate
*** This bug has been marked as a duplicate of 93508 ***
Status: NEW → RESOLVED
Closed: 21 years ago
Resolution: --- → DUPLICATE
Target Milestone: Bugzilla 2.20 → ---
QA Contact: matty_is_a_geek → default-qa
You need to log in before you can comment on or make changes to this bug.