Anybody can use anybody's SID with no consequences

Bug #244668 reported by Pietry
This bug report is a duplicate of:  Bug #244592: Need to verify message sources. Edit Remove
254
Affects Status Importance Assigned to Milestone
eHub
Fix Committed
Undecided
Unassigned

Bug Description

I can use user commands to send a message like BMSG somesid message, where somesid can be some operator's SID. In this case, I can talk in anybody's name, but even more, I can even take all the hub commands. This is an extreme security vulnerability.

Revision history for this message
CyB (viktor.balazs) wrote :
Changed in ehub:
status: New → Fix Committed
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.