BMO/Recent Changes

< BMO
Revision as of 01:53, 5 February 2026 by DaveLawrence (talk | contribs) (→‎2026-02-04)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

Recent Changes

2026-02-04

release-20260204.1

  • bug 2009883 [HackerOne] [Bugzilla] Account Takeover via Side-Channel Attack
  • bug 2012069 [HackerOne] unauthenticated blind SQL injection in search feature
  • bug 1764214 add a warning that the BMO uplift request flow will soon be deprecated

2026-01-20

release-20260120.1

  • bug 2009746 Whine events allow newlines in subject line which can be used to inject email headers
  • bug 1996136 Create a new cron script (weekly) that accesses the Recorded Future API and looks for compromised BMO accounts
  • bug 2007378 [HackerOne] Path traversal on bugzilla.mozilla.org via improper path canonicalization leads to arbitrary content loading
  • bug 2009837 After recent update sitemap extensions is including improperly formatted urls in the sitemap gz files

2025-12-16

release-20251216.1

  • bug 2005835 Please add a markdown preview option to the description field of the Client Bug Bounty Form
  • bug 1931686 don't preselect a component in the form to file a new bug
  • bug 2004722 Cannot expand hidden comment any more, when not logged in

2025-12-04

release-20251204.1

  • bug 2004060 Sometimes comment is posted twice due to mid-air collision for non editbugs users

2025-12-03

release-20251203.1

  • bug 2003859 Need info is not cleared after submitting a new comment

Archive