You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Jul 24, 2021. It is now read-only.
Reporter: miki [Submitted to the original trac issue database at 11.26pm, Monday, 24th April 2006]
cut from my public user page after adding a file:
<local full path deleted>\apotek2.gpx ... (0 points) ... 0 hours ago PENDING
second part of apotek, torvegade, kongensgade, havnegade, englandsgade, borgergade, jyllandsgade, havnegade, strandbygade, skolegade, stormgade, nrregade, jernbanegade, nrrebrogade, strandbykirkevej, langelandsvej, stergade, jagtvej, storegade, wessel
by miki in: esbjerg denmark danmark
After adding a new public file it's full local path on my machine is shown on my public gps trace page (http://www.openstreetmap.org/traces/user/miki). This is probably only during the pending period as my other completed traces only show their file name.
I consider it a security issue as it could, as in my case, reveal local servername and network drive shares.
Mikkel
The text was updated successfully, but these errors were encountered:
Author: miki [Added to the original trac issue at 1.18pm, Tuesday, 25th April 2006]
Okay, my trace is not pending anymore, but still full path is shown. This must be the result of a really fresh change as it is also an issue on the Public GPS trace page (http://www.openstreetmap.org/traces) for the two most recent traces...
Seems plausible, I've uploaded my other traces using Firefox and Konqueror, but unfortunately I'm stuck to IE at work.
A bit strange that only 8 of the 200 most recent traces was uploaded using IE, is this consistent with browser stats? Or maybe there are other prerequisites for this bug?
Where should I look to try to fix this? I would also like to hack at the editor applet at some point when I've become more familiar with this new playground :)
Reporter: miki
[Submitted to the original trac issue database at 11.26pm, Monday, 24th April 2006]
cut from my public user page after adding a file:
After adding a new public file it's full local path on my machine is shown on my public gps trace page (http://www.openstreetmap.org/traces/user/miki). This is probably only during the pending period as my other completed traces only show their file name.
I consider it a security issue as it could, as in my case, reveal local servername and network drive shares.
Mikkel
The text was updated successfully, but these errors were encountered: