Comment 1 for bug 1654598

Revision history for this message
Ben Swartzlander (bswartz) wrote :

Recommended workaround for this bug: don't share the UUIDs of shares with other tenants.

Risk for this bug is fairly low because UUIDs are impossible to guess and a successful security breach would require obtaining the UUIDs using another security exploit. Also, this bug leaks sensitive information but doesn't allow actual access to the data unless a separate exploit is used to bypass share access control.