Skip to content

Security: Regular User is allowed to view and manage list of subscriptions belonging to a different user #28

@jfrerich

Description

@jfrerich

From GH Comment: #5 (review)

6) Regular User is allowed to view and manage list of subscriptions belonging to a different user.

Severity: Low

Steps:

  • Login as User1 on Mattermost.
  • Connect to Bitbucket as User1.
  • Subscribe to few private repositories using the command /bitbucket subscribe user1/repo1
  • On another browser, login as User2 with low priviliges and visit the same channel.
  • Check subscriptions /bitbucket subscribe list and notice that it still displays repo1 which is a private repo of user1.
  • Unsubscribe using the command /bitbucket unsubscribe user1/repo1 and notice that user is allowed to change the subscription belonging to a different user.

Expected: Subscriptions should be user based. Only the owner of the subscription should be allowed to view or unsubscrib

Metadata

Metadata

Assignees

No one assigned

    Labels

    Help WantedCommunity help wantedType/EnhancementNew feature or improvement of existing featureUp For GrabsReady for help from the community. Removed when someone volunteers

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions