gitlab-org--gitlab-foss/changelogs/unreleased/redact-links-dev.yml
Jan Provaznik c1c1496405 Redact unsubscribe links in issuable texts
It's possible that user pastes accidentally also unsubscribe link
which is included in footer of notification emails. This unsubscribe
link contains personal token which attacker then use to act as the
original user (e.g. for sending comments under his/her identity).
2018-10-23 21:20:20 +02:00

5 lines
94 B
YAML

---
title: Redact personal tokens in unsubscribe links.
merge_request:
author:
type: security