#65158 closed defect (bug) (invalid)
Tortoise appears to be granting access to folders that don't belong to the user
| Reported by: |
|
Owned by: | |
|---|---|---|---|
| Milestone: | Priority: | normal | |
| Severity: | major | Version: | 6.9.4 |
| Component: | General | Keywords: | |
| Focuses: | Cc: |
Description
I don't know what happened, but it seems to be entirely wrong.
First image: my own folder.
Second image: a glimpse on a folder that don't belong to me.
If this is nothing to worry about, I apologize for opening this ticket.
I'm using Windows 10 and the latest version of Tortoise.
Attachments (2)
Change History (6)
#1
@
5 weeks ago
- Resolution set to invalid
- Status changed from new to closed
I apologize for opening this ticket. After further investigation, I realized that the WordPress.org SVN repository is public and read-accessible to everyone by design. What I saw was simply another plugin's folder in the public repository. iT's not a security issue. I'm closing this ticket as invalid. Sorry for the noise.
#2
follow-up:
↓ 3
@
5 weeks ago
@pontocinza
A couple of comments for next time:
- Bugs/feature requests for the wordpress.org sites would rather belong under https://meta.trac.wordpress.org/
- If you believe you've stumbled upon a security issue in WordPress core or the wordpress.org network, then you should not report it publicly, but instead use https://hackerone.com/wordpress - this would allow the security team to investigate and fix problems before they get widely known.
#3
in reply to:
↑ 2
@
5 weeks ago
Understood. Thank you.
Replying to tobifjellner:
@pontocinza
A couple of comments for next time:
- Bugs/feature requests for the wordpress.org sites would rather belong under https://meta.trac.wordpress.org/
- If you believe you've stumbled upon a security issue in WordPress core or the wordpress.org network, then you should not report it publicly, but instead use https://hackerone.com/wordpress - this would allow the security team to investigate and fix problems before they get widely known.
My own folder.