Happy BMO Push Day!

the following changes have been pushed to bugzilla.mozilla.org:

  • [1253483] MozReview.attachments() doesn’t create flags on new attachments
  • [1254542] Reflected XSS in comment-remo-form-payment.txt page
  • [1254675] bug_modal template fails to escape format parameter
  • [1254227] MozReview auth delegation allows sending out phishing mails via Bugzilla
  • [1253914] Cross domain referer leakage when resetting the user password
  • [1252578] CSRF and SELECT-only SQL execution attack against query_database.html

discuss these changes on mozilla.tools.bmo.


About dlawrence

Currently I work mostly on Bugzilla for the Mozilla Corporation and before that I worked for many years for Red Hat, Inc. I love playing with new technologies such as Linux, mobile devices, as well as constantly trying to improve my novice programming skills.

