Any one can purchase Books, DVD and tees from your e-store without paying nothing. #38697
Labels
No Label
legacy module
Rendering & Cycles
legacy module
User Interface
legacy project
Cycles
legacy project
Documentation
legacy project
Infrastructure: blender.org
legacy project
Infrastructure: Blender Web Assets
legacy project
Infrastructure: Websites
legacy project
User Interface
Priority
High
Priority
Low
Priority
Normal
Priority
Unbreak Now!
Status
Archived
Status
Confirmed
Status
Duplicate
Status
Needs Triage
Status
Resolved
Type
Bug
Type
Design
Type
Known Issue
Type
Report
Type
To Do
No Milestone
No project
No Assignees
4 Participants
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: infrastructure/blender-org#38697
Loading…
Reference in New Issue
Block a user
No description provided.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
System Information
Operating system and graphics card
Windows 8, Radeon AMD
Blender Version
Broken: (example: 2.69.7 4b206af, see splash screen)
Worked: (optional)
Short description of error
Any one can purchase Books, DVD and tees from your e-store without paying nothing by simply modifying the http headers.
Exact steps for others to reproduce the error
Based on a (as simple as possible) attached .blend file with minimum amount of steps
Changed status to: 'Open'
Added subscriber: @root-3
Added subscriber: @Sergey
Hey there Bhaskar,
thanks for reporting the issue. We are checking on it, but we have additional backend checks, so that such orders don't actually get shipped.
Hello Fsiddi,
Good to hear that you have backend checks but patch the vulnerability as soon as possible so that no one can take advantages on it. If you need any further help please let me know I would be very happy to help you.
Thank You.
If you could mail me privately at francesco@blender.org it would be great.
Changed status from 'Open' to: 'Archived'
The issue is known and being taken care of.
Added subscriber: @Blendify
Changed status from 'Archived' to: 'Resolved'
I assume this has been fixed
Changed status from 'Resolved' to: 'Archived'
This is a known issue, we have backend checks to take care of it.