[wp-trac] [WordPress Trac] #16778: wordpress is leaking user/blog information during wp_version_check()

WordPress Trac wp-trac at lists.automattic.com
Sun Jul 17 10:24:48 UTC 2011


#16778: wordpress is leaking user/blog information during wp_version_check()
----------------------------+------------------------------
 Reporter:  investici       |       Owner:
     Type:  enhancement     |      Status:  reopened
 Priority:  normal          |   Milestone:  Awaiting Review
Component:  Administration  |     Version:
 Severity:  minor           |  Resolution:
 Keywords:  legal           |
----------------------------+------------------------------

Comment (by investici):

 @toscho: thanks for your patch, it is a step in the right direction. Any
 plans for review/inclusion in core?

 whether this bug is fixed by that patch is debatable though, we'd much
 prefer having the users opt-in before leaking so much information or at
 least make the users/admins aware of the fact (and the reason why?) that
 information not related to check for updates is sent while checking for
 updates.

 what is the best way to get consensus (and a fix) for this from the wp
 developers?

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/16778#comment:20>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list