Make WordPress Core

Opened 5 weeks ago

Closed 5 weeks ago

Last modified 4 weeks ago

#65158 closed defect (bug) (invalid)

Tortoise appears to be granting access to folders that don't belong to the user

Reported by: pontocinza's profile pontocinza Owned by:
Milestone: Priority: normal
Severity: major Version: 6.9.4
Component: General Keywords:
Focuses: Cc:

Description

I don't know what happened, but it seems to be entirely wrong.

First image: my own folder.
Second image: a glimpse on a folder that don't belong to me.

If this is nothing to worry about, I apologize for opening this ticket.
I'm using Windows 10 and the latest version of Tortoise.

Attachments (2)

2026-05-03_112055.png (56.7 KB) - added by pontocinza 5 weeks ago.
My own folder.
2026-05-03_112116.png (54.8 KB) - added by pontocinza 5 weeks ago.
This folder doesn't belong to me.

Download all attachments as: .zip

Change History (6)

@pontocinza
5 weeks ago

My own folder.

@pontocinza
5 weeks ago

This folder doesn't belong to me.

#1 @pontocinza
5 weeks ago

  • Resolution set to invalid
  • Status changed from new to closed

I apologize for opening this ticket. After further investigation, I realized that the WordPress.org SVN repository is public and read-accessible to everyone by design. What I saw was simply another plugin's folder in the public repository. iT's not a security issue. I'm closing this ticket as invalid. Sorry for the noise.

#2 follow-up: @tobifjellner
5 weeks ago

@pontocinza
A couple of comments for next time:

  1. Bugs/feature requests for the wordpress.org sites would rather belong under https://meta.trac.wordpress.org/
  2. If you believe you've stumbled upon a security issue in WordPress core or the wordpress.org network, then you should not report it publicly, but instead use https://hackerone.com/wordpress - this would allow the security team to investigate and fix problems before they get widely known.

#3 in reply to: ↑ 2 @pontocinza
5 weeks ago

Understood. Thank you.

Replying to tobifjellner:

@pontocinza
A couple of comments for next time:

  1. Bugs/feature requests for the wordpress.org sites would rather belong under https://meta.trac.wordpress.org/
  2. If you believe you've stumbled upon a security issue in WordPress core or the wordpress.org network, then you should not report it publicly, but instead use https://hackerone.com/wordpress - this would allow the security team to investigate and fix problems before they get widely known.

#4 @sabernhardt
4 weeks ago

  • Milestone Awaiting Review deleted
Note: See TracTickets for help on using tickets.