You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
darraghoriordan
changed the title
Leaking session authentication in the urls posted in new comment bodies
Leaking session / authorization in the urls posted in new comment bodies
Apr 14, 2023
Hey,
It looks like the link that is posted in new issue bodies leaks the session of the first commenter?
I can click on that link, and if the person is still logged in to github via utterances, i can post a comment as them.
The link that the bot creates for issue bodies should not include the "utterances=" query string containing the session??
The text was updated successfully, but these errors were encountered: