[Bug 49090] Login API doesn't prevent getting csrf tokens via jsonp

2013-09-03 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=49090 Chris Steipp changed: What|Removed |Added Status|NEW |RESOLVED Group|security

[Bug 49090] Login API doesn't prevent getting csrf tokens via jsonp

2013-09-03 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=49090 --- Comment #14 from Gerrit Notification Bot --- Change 82527 merged by jenkins-bot: SECURITY: Prevent tokens in jsonp mode https://gerrit.wikimedia.org/r/82527 -- You are receiving this mail because: You are the assignee for the bug. You ar

[Bug 49090] Login API doesn't prevent getting csrf tokens via jsonp

2013-09-03 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=49090 --- Comment #17 from Gerrit Notification Bot --- Change 82545 had a related patch set uploaded by CSteipp: SECURITY: Prevent tokens in jsonp mode https://gerrit.wikimedia.org/r/82545 -- You are receiving this mail because: You are the assign

[Bug 49090] Login API doesn't prevent getting csrf tokens via jsonp

2013-09-03 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=49090 --- Comment #18 from Gerrit Notification Bot --- Change 82537 merged by CSteipp: SECURITY: Prevent tokens in jsonp mode https://gerrit.wikimedia.org/r/82537 -- You are receiving this mail because: You are the assignee for the bug. You are on

[Bug 49090] Login API doesn't prevent getting csrf tokens via jsonp

2013-09-03 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=49090 --- Comment #15 from Gerrit Notification Bot --- Change 82537 had a related patch set uploaded by CSteipp: SECURITY: Prevent tokens in jsonp mode https://gerrit.wikimedia.org/r/82537 -- You are receiving this mail because: You are the assign

[Bug 49090] Login API doesn't prevent getting csrf tokens via jsonp

2013-09-03 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=49090 Gerrit Notification Bot changed: What|Removed |Added Status|RESOLVED|PATCH_TO_REVIEW Reso

[Bug 49090] Login API doesn't prevent getting csrf tokens via jsonp

2013-09-03 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=49090 --- Comment #16 from Gerrit Notification Bot --- Change 82541 had a related patch set uploaded by CSteipp: SECURITY: Prevent tokens in jsonp mode https://gerrit.wikimedia.org/r/82541 -- You are receiving this mail because: You are the assign

[Bug 49090] Login API doesn't prevent getting csrf tokens via jsonp

2013-09-03 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=49090 --- Comment #19 from Gerrit Notification Bot --- Change 82545 merged by jenkins-bot: SECURITY: Prevent tokens in jsonp mode https://gerrit.wikimedia.org/r/82545 -- You are receiving this mail because: You are the assignee for the bug. You ar

[Bug 49090] Login API doesn't prevent getting csrf tokens via jsonp

2013-09-03 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=49090 --- Comment #20 from Gerrit Notification Bot --- Change 82541 merged by jenkins-bot: SECURITY: Prevent tokens in jsonp mode https://gerrit.wikimedia.org/r/82541 -- You are receiving this mail because: You are the assignee for the bug. You ar

[Bug 49090] Login API doesn't prevent getting csrf tokens via jsonp

2013-09-04 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=49090 Andre Klapper changed: What|Removed |Added Status|PATCH_TO_REVIEW |RESOLVED Resolution|---

[Bug 49090] Login API doesn't prevent getting csrf tokens via jsonp

2013-09-05 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=49090 --- Comment #22 from Chris Steipp --- This issue was assigned CVE-2013-4302 -- You are receiving this mail because: You are the assignee for the bug. You are on the CC list for the bug. ___ Wikibugs