Need to verify message sources

Bug #244592 reported by Szabolcs Molnár
262
Affects Status Importance Assigned to Milestone
eHub
Fix Committed
High
CyB

Bug Description

The hub required to verify if the ADC commands' originating SID field is the same as the user's own sid. So users shouldn't be able to talk in someone else's name.

for example, I can send BMSG ABCD test even if my sid is not ABCD

Szabolcs Molnár (fleet)
Changed in ehub:
importance: Undecided → High
CyB (viktor.balazs)
Changed in ehub:
assignee: nobody → viktor.balazs
status: New → Fix Committed
CyB (viktor.balazs)
Changed in ehub:
milestone: none → 0-4-0
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.