IRC-Bot exposes information
Medium
P
Phabricator
Submitted None
Actions:
Reported by
luke081515
Vulnerability Details
Technical details and impact analysis
You can setup the IRC-Bot, and set it into private channels, so that it posts only information about tasks into private channels. Example:
<Human> T698
<Bot> T698: Task title - https://url.example.org/T698
The problem is, that, if the bot is online in IRC, you can send him task numbers via private messages, and then he exposes the title of tasks without access control.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Information Disclosure