Opened 17 years ago

Closed 16 years ago

Last modified 16 years ago

#7391 closed defect (wontfix)

renamed plugin disable commands in trac.ini [components] silently fail, a security issue

Reported by: anonymous Owned by:
Priority: low Milestone:
Component: general Version: 0.11
Severity: trivial Keywords: security
On upgrading to trac 0.11, I found I had to rename:




The problem here is that I found this by noticing that trac 0.11 was allowing uploads.

There was no complaint about the old disabled line not being relevant any more, and no upgrade documentation to warn that if we locked things down in webadmin we now need to rename the lines in the config file.

I think the lack of warning (in code or in documentation) is a security risk to people upgrading.

Change History (7)

comment:1 by anonymous, 17 years ago

Owner: set to anonymous
Status: newassigned


comment:2 by Piotr Kuczynski <piotr.kuczynski@…>, 17 years ago

Component: generaladmin/web
Keywords: security added
Milestone: 0.11.1
Severity: normalcritical
Version: 0.11

comment:3 by Christian Boos, 16 years ago

Priority: normallow
Severity: criticalmajor

Well, hm, I think it's a bit late to bother with upgrades from WebAdmin, but if someone contributes a patch, why not.

comment:4 by Remy Blank, 16 years ago

I have been tempted several times to just close this as wontfix. It's the site admin's job to check the site thoroughly after an upgrade, after all. At most, add a warning to the upgrade instructions for 0.11.

comment:5 by anonymous, 16 years ago

Component: admin/webgeneral
Severity: majortrivial
Status: assignednew

comment:6 by Remy Blank, 16 years ago

Milestone: 0.11.3
Resolution: wontfix
Status: newclosed

No patch contributed (comment:3), closing as wontfix.

comment:7 by Remy Blank, 16 years ago

Owner: anonymous removed

