Bugzilla outstanding requests email leaks secure bug summary

RESOLVED INVALID

Status

()

bugzilla.mozilla.org
General
--
major
RESOLVED INVALID
5 years ago
5 years ago

People

(Reporter: bc, Unassigned)

Tracking

Production

Details

(Reporter)

Description

5 years ago
1. file a bug and assign it to the security group
2. set a needinfo request
3. wait for the outstanding request

the outstanding request email will contain the full summary of the bug instead of "Secure bug".

Updated

5 years ago
Assignee: whining → nobody
Component: Whining → General
Product: Bugzilla → bugzilla.mozilla.org
QA Contact: default-qa
Version: unspecified → Production
You don't have a key set?  Mine have the entire mail encrypted when one of the bugs in the list is secured. So when it can't encrypt it's not hiding it?
(Reporter)

Comment 2

5 years ago
I have a key set and my normal secure bug mail is encrypted and the subject does not contain the bug summary. The whine email for a secure bug sends the actual bug summary instead of the "Secure Bug" replacement text.
(Reporter)

Comment 3

5 years ago
Oh, doh. The whine email itself is fully encrypted. sorry, -> invalid.
Status: NEW → RESOLVED
Last Resolved: 5 years ago
Resolution: --- → INVALID
You need to log in before you can comment on or make changes to this bug.