ports/databases/mantis/files/patch-config__defaults__inc.php
Dan Langille 358229bc25 patch with security fix for CVE-2015-5059
Submitted by: Torsten Zuhlsdorff & Jason Unovitch
PR: 201106 202865
Approved by: mat (mentor)
Differential Review: D4196
2015-12-23 21:20:51 +00:00

17 lines
552 B
PHP

--- config_defaults_inc.php.orig 2015-11-02 10:57:53 UTC
+++ config_defaults_inc.php
@@ -2347,9 +2347,13 @@
/**
* Threshold needed to view project documentation
+ * Note: setting this to ANYBODY will let any user download attachments
+ * from private projects, regardless of their being a member of it.
+ * @see $g_enable_project_documentation
+ * @see $g_upload_project_file_threshold
* @global int $g_view_proj_doc_threshold
*/
- $g_view_proj_doc_threshold = ANYBODY;
+ $g_view_proj_doc_threshold = VIEWER;
/**
* Site manager