Comment 1 for bug 383085

Revision history for this message
Fumihito YOSHIDA (hito) wrote :

FYI:
Patch aproach for hotfix are avaialble, but any actual patch is not written.
http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2009-1339#Minimal_Hotfix_for_TWiki_Product

Aproachs are:
  1) changing twiki-apache conf (/etc/twiki/apache.conf), it prevent from GET access
     for sensitive previledged pages.
  2) changing templates files. it minimal included:
    * twiki/templates/messages.tmpl
    * twiki/templates/oopsmore.tmpl
    * twiki/templates/registerconfirm.tmpl