Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

2024 Audit - SEC-01-015 WP1: Potential Race Condition in Source Creation #7292

Open
zenmonkeykstop opened this issue Oct 29, 2024 · 0 comments

Comments

@zenmonkeykstop
Copy link
Contributor

A potential race condition was identified in the SecureDrop platform source creation
process. The create_source_user function does not prevent simultaneous creation of
sources with identical journalist designations. This can lead to multiple sources having
the same designation, causing confusion or information leakage.

We will be investigating this further.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant