mirror of
https://github.com/ether/etherpad-lite.git
synced 2025-05-02 13:19:14 -04:00
PadMessageHandler: Don't trust user-provided padId
This commit is contained in:
parent
bdbde88fed
commit
ba370b0e05
4 changed files with 115 additions and 8 deletions
|
@ -2,6 +2,11 @@
|
|||
|
||||
(not yet released)
|
||||
|
||||
### Security fixes
|
||||
|
||||
* Fixed a vunlerability in the `CHANGESET_REQ` message handler that allowed a
|
||||
user with any access to read any pad if the pad ID is known.
|
||||
|
||||
### Notable enhancements and fixes
|
||||
|
||||
* Fixed a bug that caused all pad edit messages received at the server to go
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue