Bug 97199

Summary: bugzilla let me make public bug private with random user on CC list
Product: [Community] Bugzilla Reporter: Jonathan Kamens <jik>
Component: Bugzilla GeneralAssignee: PnT DevOps Devs <hss-ied-bugs>
Status: CLOSED NOTABUG QA Contact: David Lawrence <dkl>
Severity: medium Docs Contact:
Priority: medium    
Version: 2.18   
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2007-11-02 20:05:23 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Jonathan Kamens 2003-06-11 14:08:07 UTC
I just added a comment to bug 87606: "This is still broken in
imap-2002b-6.  Surely you can't ship the next release with this still
broken!"  Because I mentioned the next release, I clicked the box to
make the bug private before committing my changes.  I noticed that
when I subsequently committed my changes, E-mail about them was sent
to someone on the CC list of the bug.

It appears that if a bug is converted from public to private, people
who added themselves to the CC list before the conversion will
continue to receive E-mail about the bug, and said E-mail may contain
private information.

This seems like a problem.

Comment 1 David Lawrence 2006-04-08 17:52:17 UTC
Red Hat's current Bugzilla version is 2.18. I am moving all older open bugs to
this version. Any bugs against the older versions will need to be verified that
they are still bugs. This will help me also to sort them better.

Comment 2 David Lawrence 2007-11-02 20:05:23 UTC
The Cc list accessible checkbox needs to be unchecked when making the group
change, otherwise this will occur. This is a Bugzilla design issue and is best
addressed with the upstream community at http://www.bugzilla.org.