-
-
Notifications
You must be signed in to change notification settings - Fork 4.9k
Closed
Labels
bugA problem with current functionality, as opposed to missing functionality (enhancement)A problem with current functionality, as opposed to missing functionality (enhancement)frozen-due-to-ageIssues closed and untouched for a long time, together with being locked for discussionIssues closed and untouched for a long time, together with being locked for discussion
Milestone
Description
A vulnerability report was submitted to the effect that the untrusted flag doesn't properly prevent combining with introducer, thus allowing the supposedly untrusted device to introduce trusted devices into the cluster and causing a data leak. Since this is a misconfiguration that needs to happen on the trusted side, I decided it's low impact enough to be published as a public issue while we're fixing it.
This may also apply to other settings, such as auto-accepting folders which makes no sense from an untrusted device.
Originally reported by @vibs29
Metadata
Metadata
Assignees
Labels
bugA problem with current functionality, as opposed to missing functionality (enhancement)A problem with current functionality, as opposed to missing functionality (enhancement)frozen-due-to-ageIssues closed and untouched for a long time, together with being locked for discussionIssues closed and untouched for a long time, together with being locked for discussion