Activity log for bug #1164575
Date | Who | What changed | Old value | New value | Message |
---|---|---|---|---|---|
2013-04-04 15:34:15 | Lebbeous Fogle-Weekley | bug | added bug | ||
2013-04-04 16:05:21 | Mike Rylander | attachment added | jsonNumberToDBString.fix.patch https://bugs.launchpad.net/evergreen/+bug/1164575/+attachment/3621078/+files/jsonNumberToDBString.fix.patch | ||
2013-04-14 17:07:12 | Ben Shum | evergreen: status | New | Confirmed | |
2013-04-17 19:38:53 | Galen Charlton | nominated for series | evergreen/2.1 | ||
2013-04-17 19:38:53 | Galen Charlton | bug task added | evergreen/2.1 | ||
2013-04-17 19:38:53 | Galen Charlton | nominated for series | evergreen/2.2 | ||
2013-04-17 19:38:53 | Galen Charlton | bug task added | evergreen/2.2 | ||
2013-04-17 19:38:53 | Galen Charlton | nominated for series | evergreen/2.3 | ||
2013-04-17 19:38:53 | Galen Charlton | bug task added | evergreen/2.3 | ||
2013-04-17 19:39:02 | Galen Charlton | evergreen/2.2: milestone | 2.2.8 | ||
2013-04-17 19:39:07 | Galen Charlton | evergreen/2.3: milestone | 2.3.6 | ||
2013-04-17 19:40:13 | Galen Charlton | evergreen/2.1: milestone | 2.1.6 | ||
2013-04-17 19:40:23 | Galen Charlton | evergreen/2.1: status | New | Fix Committed | |
2013-04-17 19:40:28 | Galen Charlton | evergreen/2.1: importance | Undecided | Critical | |
2013-04-17 19:40:30 | Galen Charlton | evergreen/2.2: importance | Undecided | Critical | |
2013-04-17 19:40:31 | Galen Charlton | evergreen/2.3: importance | Undecided | Critical | |
2013-04-17 19:40:34 | Galen Charlton | evergreen/2.3: status | New | Fix Committed | |
2013-04-17 19:40:36 | Galen Charlton | evergreen/2.2: status | New | Fix Committed | |
2013-04-17 19:57:06 | Mike Rylander | evergreen: status | Confirmed | Fix Committed | |
2013-04-17 20:00:45 | Galen Charlton | description | Probably all versions, but confirmed in master using srfsh: request open-ils.pcrud open-ils.pcrud.search.acplg "AUTHTOKEN" {"owner": ["1);create table asset.security_fail (blah int);--", 1]} Thanks to Dan Scott for noticing something fishy in his logs that made this obvious. | Probably all versions, but confirmed in master using srfsh: {EXAMPLE OF SQL INJECTION} Thanks to Dan Scott for noticing something fishy in his logs that made this obvious. | |
2013-04-17 20:01:42 | Galen Charlton | information type | Private Security | Public Security | |
2013-04-18 13:54:32 | Ben Shum | evergreen/2.1: status | Fix Committed | Fix Released | |
2013-04-18 13:54:34 | Ben Shum | evergreen/2.2: status | Fix Committed | Fix Released | |
2013-04-18 13:54:36 | Ben Shum | evergreen/2.3: status | Fix Committed | Fix Released | |
2013-05-19 20:15:14 | Ben Shum | evergreen: status | Fix Committed | Fix Released |