Bug 7206

Summary: query.cgi does BAD thinks when Bugzilla_logincookie is invalid!!!
Product: [Community] Bugzilla Reporter: Aleksey Nogin <aleksey>
Component: Bugzilla GeneralAssignee: David Lawrence <dkl>
Status: CLOSED CURRENTRELEASE QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: 2.1rKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 1999-11-22 17:00:28 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:

Description Aleksey Nogin 1999-11-21 19:02:07 UTC
Do a little experiment:

1) Set Bugzilla_login to ayn2
2) Set Bugzilla_logincookie to something invalid (like 0). Now go to
query.cgi

BAD things happen:

1) All my saved queries are available (security issue!).
2) It does not suggest to log in at the top of the page (which it does when
Bugzilla_login is not set).
3) It does not give option to log out and log in as somebody else at the
bottom of the page (which it does when it thinks I am logged in).

Comment 1 David Lawrence 1999-11-22 17:00:59 UTC
Ok, i think i have this one fixed from what i can tell at my end. Please try to
recreate this on your end and let me know if it still occurs. Thanks.