Ticket #2342 (closed defect: fixed)
security issue with repoze in Turbogears 2.0.x
| Reported by: | cd34 | Owned by: | |
|---|---|---|---|
| Priority: | normal | Milestone: | |
| Component: | TurboGears | Version: | 2.0 |
| Severity: | normal | Keywords: | |
| Cc: |
Description
I've forwarded a scenario that I've verified is exploitable to Mark Ramm via the email address he's subscribed to in groups.google.com/turbogears
I couldn't find a security email address on the website.
Change History
Note: See
TracTickets for help on using
tickets.
Does this involve the Repoze auth_tkt cookie? If so, we've found the issue as well, and it's severely in need of correction.