7786 |
Invalidate pwd reset tokens after email change |
closed |
Heith Seewald
|
security, sf-2 |
Dave Brondsema |
0 |
|
7545 |
return_to param should be validated for relative URLs |
closed |
Cory Johns
|
security, sf-1 |
Dave Brondsema |
0 |
|
7543 |
Password recovery should not confirm email addr existance |
closed |
Alexander Luberg
|
security, sf-1 |
Dave Brondsema |
0 |
|
7528 |
XSS on wiki page and preview |
closed |
Dave Brondsema
|
security, p1, sf-2 |
|
0 |
|
7026 |
Require POST for follow/unfollow actions |
closed |
Cory Johns
|
activitystreams, security, sf-1 |
Dave Brondsema |
0 |
|
6889 |
XSS on /p/add_project/ |
closed |
Dave Brondsema
|
support, p1, security, sf-1 |
|
0 |
|
6604 |
IE9 json parsing vulnerability |
closed |
Dave Brondsema
|
security, sf-1 |
Cory Johns |
0 |
|
6469 |
Insecurity in Admin Overview Form [ss4721] |
closed |
Tim Van Steenburgh
|
support, p1, security, sf-1 |
|
0 |
|
6219 |
Make tracker email notifications respect private tickets |
closed |
Tim Van Steenburgh
|
security, sf-2 |
Dave Brondsema |
0 |
|
5887 |
Per-artifact ACLs not checked on _discuss URLs |
closed |
Dave Brondsema
|
p1, security, sf-2 |
|
0 |
|