-
15 hours ago
-
Requesting changes for a high-severity account-takeover vulnerability: manual GitHub attribution mappings can register attacker-controlled verified recovery emails on other OneDev accounts. See the inline finding.
Reviewed the current PR head, including import permissions, identity mapping, email persistence, password recovery, and import feedback. Local compilation passed with
mvn -pl server-plugin/server-plugin-import-github -am -DskipTests compile; tests were not run. CI build OD-8403 failed before execution withNo applicable job executor. No code changes were made. -
-
-
@crayson09 as indicated by the AI bot, there is a critical security vulnerability here regarding adding verified email to OneDev user account, issue importing can be executed by any user on their own projects.
Also I am curious why this is needed while importing issues.
| Submitter | Ole H |
| Target | main |
| Source | forks/crayson09/server:feature/improve-github-import |
Improves how GitHub identities are mapped to OneDev accounts during import.
Issue import
Commit / PR-merge attribution
Applies to both the project importer and the standalone issue importer. Import summary now reports linked and conflicting commit emails.