bug imports create new users with non-hidden email addresses
Bug #700483 reported by
Peter Clifton
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Launchpad itself |
Triaged
|
High
|
Unassigned |
Bug Description
When importing bugs, "dummy" users are created which point to the user's email address from the bug import.
When accessing the "dummy" user account and clicking the "Are you <username>?" link, then click through the continue button, Launchpad tells you what email address it sent the confirmation code to.
Whilst this may be useful to debug mail delivery problems, it is a potential leak of user information which might be useful to spammers.
summary: |
- Email address leaked by account merge request + bug imports create new users with non-hidden email addresses |
Changed in launchpad: | |
status: | Incomplete → Triaged |
importance: | Undecided → High |
tags: | added: privacy |
To post a comment you must log in.
The link which results in the link is found from this page:
https:/ /launchpad. net/people/ +requestmerge? field.dupe_ person=<username>