•  
      request #43704 Artifact disclosure to a mentioned user via email notifications
    Infos
    #43704
    Antoine Sauzeau (antoinesauzeau)
    2025-07-21 16:11
    2025-07-10 18:02
    45393
    Details
    Artifact disclosure to a mentioned user via email notifications

    When users are mentioned in the comments of an artifact, they receive an email notification even if they do not have the necessary permissions to access the artifact. The notification sent may contain the entire content of the artifact if field permissions allow it.

    Impact

    Users may potentially access confidential information from artifacts that they are not authorized to view.

    CVSSv3.1 score: 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)

    Exploitation

    1. Create an artifact in a tracker where access is restricted to certain users.
    2. Comment something in this artifact and mentioning one of the users who does not have access rights.
    3. Open the mailbox associated with this user's account.

    References

    CWE 863
    OWASP Broken Access Control
    CVE-2025-53902

    Trackers
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Antoine Sauzeau (antoinesauzeau)
    Closed
    2025-07-15
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2025-07-15 18:34

    CVE-2025-53902 has been assigned to this issue.


    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    User avatar
    Thomas Gerbet (tgerbet)2025-07-11 08:12
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes