|
|
|
|
|
by rogerbinns
4761 days ago
|
|
They had one I reported Oct 2010, took a while to convince was an issue and they finally fixed a few months after saying they would. The URLS for attachments to private issues in private repos were guessable and publicly accessible if you guessed right (ie no authentication for them). The URLs were like this
https://bitbucket-assetroot.s3.amazonaws.com/<username&#... Obviously a bit tedious to guess for humans, but no big deal for computers. |
|