View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
0000247 | opensim-SC | Bug | public | 2021-06-16 08:54 | 2021-08-03 02:00 |
Reporter | onefang | Assigned To | onefang | ||
Priority | immediate | Severity | major | Reproducibility | sometimes |
Status | resolved | Resolution | fixed | ||
Product Version | 0.9.0.2 | ||||
Target Version | 0.9.1.1 | Fixed in Version | 0.9.1.1 | ||
Summary | 0000247: Anyone can drag stuff out of boxes they don't own, to places they have no create rights, then edit them. | ||||
Description | Reported by Syldra. | ||||
Steps To Reproduce | Go to Destiny Shopping sim. "stuff Ethan imported 06-30-2019 - potted plants" (which isn't owned by you) Drag things out of that and onto the floor. Edit the things. Click the New Script button, see the New Script appear in the contents, see the "script running" output. Delete the things. | ||||
Additional Information | The object remains the same owner, though you can edit it. You can't edit other stuff owned by the same person. | ||||
Tags | No tags attached. | ||||
Note, this is non gods allowed to do this. | |
Still broken in 0.9.1.1 | |
Korgi reports it's still broken in 0.9.2. | |
So the dragging out bit isn't really a bug, coz that makes sense. It's the ownership not changing that's the bug. Coz the person that put it in the shop in the first place has creation rights in that sim. And hence after changing owner, it should refuse to rez if the new owner doesn't have create rights. But they should be able to drag directly to their own inventory. That still leaves the "you now have a glitchy object on the floor / in your inventory" part. |
|
|
|
It's the "then edit it" part that is a security bug. | |
|
|
Backported from 0.9.2 fix owner on user rez from a prim inventory to ground | |
Date Modified | Username | Field | Change |
---|---|---|---|
2021-06-16 08:54 | onefang | New Issue | |
2021-06-16 08:54 | onefang | Status | new => assigned |
2021-06-16 08:54 | onefang | Assigned To | => onefang |
2021-06-16 08:57 | onefang | Note Added: 0000345 | |
2021-06-16 09:03 | onefang | Note Added: 0000346 | |
2021-06-16 09:03 | onefang | Summary | Anyone can drag stuff out of boxes they don't own to places they have no edit rights, then edit them. => Anyone can drag stuff out of boxes they don't own to places they have no createrights, then edit them. |
2021-06-16 09:14 | onefang | Steps to Reproduce Updated | |
2021-06-16 09:15 | onefang | Note Added: 0000347 | |
2021-06-16 09:16 | onefang | Summary | Anyone can drag stuff out of boxes they don't own to places they have no createrights, then edit them. => Anyone can drag stuff out of boxes they don't own, to places they have no create rights, then edit them. |
2021-06-16 11:50 | onefang | Note Added: 0000349 | |
2021-06-16 11:54 | onefang | Note Edited: 0000349 | |
2021-06-21 20:02 | onefang | Note Added: 0000354 | |
2021-07-07 02:03 | onefang | Note Added: 0000407 | |
2021-07-07 02:34 | onefang | Note Added: 0000408 | |
2021-07-07 03:00 | onefang | View Status | public => private |
2021-08-03 02:00 | onefang | Status | assigned => resolved |
2021-08-03 02:00 | onefang | Resolution | open => fixed |
2021-08-03 02:00 | onefang | Fixed in Version | => 0.9.1.1 |
2021-08-03 02:00 | onefang | Note Added: 0000461 | |
2021-08-03 02:00 | onefang | View Status | private => public |