<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Recent changes to bugs</title><link>https://sourceforge.net/p/jedit/bugs/</link><description>Recent changes to bugs</description><atom:link href="https://sourceforge.net/p/jedit/bugs/feed.rss" rel="self"/><language>en</language><lastBuildDate>Sat, 11 Apr 2026 02:51:34 -0000</lastBuildDate><atom:link href="https://sourceforge.net/p/jedit/bugs/feed.rss" rel="self" type="application/rss+xml"/><item><title>Multiple input of "C+SEMICOLON"</title><link>https://sourceforge.net/p/jedit/bugs/4149/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Somehow jEdit understands a single stroke of "C+SEMICOLON" as three copies of it.&lt;br/&gt;
(The key "C" is the command key of mac.)&lt;/p&gt;
&lt;p&gt;Steps to Reproduce:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Launch jEdit&lt;/li&gt;
&lt;li&gt;From Menu bar, open jEdit &amp;gt; Preferences...&lt;/li&gt;
&lt;li&gt;Open the Shortcuts tab&lt;/li&gt;
&lt;li&gt;Take any command (e.g. Add Prefix and Suffix) and try to set the short cut to C+SEMICOLON&lt;/li&gt;
&lt;li&gt;Then, "C+SEMICOLON C+SEMICOLON C+SEMICOLON" is registered instead of single "C+SEMICOLON".&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Side note:&lt;br/&gt;
(1) It seems that even in the text area, the stroke "C+SEMICOLON" seems to be understood as "C+SEMICOLON C+SEMICOLON C+SEMICOLON".&lt;br/&gt;
(2) With Karabiner-Elements and other key event viewer, I checked the stroke "C+SEMICOLON" is recognized only once for other application.&lt;/p&gt;
&lt;p&gt;jEdit version: 5.7.0&lt;br/&gt;
Platform: MacOS (15.7.4（24G517）) with Intel chip&lt;br/&gt;
Java version: 25.0.1&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Yuta Suzuki</dc:creator><pubDate>Sat, 11 Apr 2026 02:51:34 -0000</pubDate><guid>https://sourceforge.netcfe9c3d11d56130896c56e6a97d7c2bd14d0c45a</guid></item><item><title>jEdit 5.7: Bug in Save-Dialog</title><link>https://sourceforge.net/p/jedit/bugs/4148/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;jEdit 5.7.0&lt;br/&gt;
Java 15.0.2&lt;br/&gt;
Windows 10&lt;/p&gt;
&lt;p&gt;Steps:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;make file ab.txt&lt;/li&gt;
&lt;li&gt;make new file&lt;/li&gt;
&lt;li&gt;do "save"&lt;/li&gt;
&lt;li&gt;in the save-dialog:&lt;ul&gt;
&lt;li&gt;click on the file ab.txt&lt;/li&gt;
&lt;li&gt;change the text in the file name field from ab.txt to a.txt&lt;/li&gt;
&lt;li&gt;click "save"&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;jEdit asks if you want to overwrite ab.txt instead of saving the new file to a.txt.&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Gilward Kukel</dc:creator><pubDate>Thu, 23 Oct 2025 05:26:00 -0000</pubDate><guid>https://sourceforge.net1cd5607951fe71449082be6c3547beddb71cdeb3</guid></item><item><title>#4147 Found Vulnerability:- IDOR (Insecure Direct Object Reference)</title><link>https://sourceforge.net/p/jedit/bugs/4147/?limit=25#fab7</link><description>&lt;div class="markdown_content"&gt;&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;status&lt;/strong&gt;: open-invalid --&amp;gt; closed-invalid&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Eric Le Lay</dc:creator><pubDate>Wed, 17 Sep 2025 12:28:03 -0000</pubDate><guid>https://sourceforge.net479315b6bad364e653447d8a60b93612cb61ac87</guid></item><item><title>#4147 Found Vulnerability:- IDOR (Insecure Direct Object Reference)</title><link>https://sourceforge.net/p/jedit/bugs/4147/?limit=25#d029</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;*Before re-testing it first Login your account  then only you will see response 200 ok:-&lt;/p&gt;
&lt;p&gt;In 6th point after modifying the account id from request you will see that response is ok in repeater, it must not happen. If somone modify the account id it must show error code. I have also send the PDF report with POC.&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">kunal waidande </dc:creator><pubDate>Tue, 16 Sep 2025 13:57:18 -0000</pubDate><guid>https://sourceforge.net621e4d4f78abf0d05acf40faadece9855ebd931f</guid></item><item><title>#4147 Found Vulnerability:- IDOR (Insecure Direct Object Reference)</title><link>https://sourceforge.net/p/jedit/bugs/4147/?limit=25#5902</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;I see you already created &lt;a href="https://sourceforge.net/p/forge/site-support/27035/"&gt;https://sourceforge.net/p/forge/site-support/27035/&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Eric Le Lay</dc:creator><pubDate>Mon, 15 Sep 2025 18:54:49 -0000</pubDate><guid>https://sourceforge.net1ac07d49490b66e276db25de39a745bbe7e88ee4</guid></item><item><title>#4147 Found Vulnerability:- IDOR (Insecure Direct Object Reference)</title><link>https://sourceforge.net/p/jedit/bugs/4147/?limit=25#6e5e</link><description>&lt;div class="markdown_content"&gt;&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Group&lt;/strong&gt;: severe bug --&amp;gt; UNUSED&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Eric Le Lay</dc:creator><pubDate>Mon, 15 Sep 2025 18:53:47 -0000</pubDate><guid>https://sourceforge.netca44936a163cdb8f7506f57c19672c4f8d407908</guid></item><item><title>#4147 Found Vulnerability:- IDOR (Insecure Direct Object Reference)</title><link>https://sourceforge.net/p/jedit/bugs/4147/?limit=25#9406</link><description>&lt;div class="markdown_content"&gt;&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;status&lt;/strong&gt;: open --&amp;gt; open-invalid&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Eric Le Lay</dc:creator><pubDate>Mon, 15 Sep 2025 18:53:27 -0000</pubDate><guid>https://sourceforge.netde7edbaff8586a200e8c8e1177a844184be87def</guid></item><item><title>Found Vulnerability:- IDOR (Insecure Direct Object Reference)</title><link>https://sourceforge.net/p/jedit/bugs/4147/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;The following API endpoint allows an attacker to change account-id in the query string and receive a valid response tied to that account.&lt;/p&gt;
&lt;p&gt;Vulnerable endpoint: GET /a/api/fastlane.json?account_id=15680&amp;amp;site_id=103240&lt;/p&gt;
&lt;p&gt;How to perform:&lt;br/&gt;
1- Go to website (https://www.jedit.org)&lt;br/&gt;
2- In home page on right side you will see sourceForge Project option.&lt;br/&gt;
3- Open burpsuit and on the intercept and in browser click on sourceForge Project option.&lt;br/&gt;
4- Forward the first and second request and then you will see bunch of requests in that request.&lt;br/&gt;
5- You that requests you will see (https://fastlane.rubiconproject.com).&lt;br/&gt;
6- Send it to repeater and change the account id.&lt;br/&gt;
7- You will see that response is 200 OK .&lt;/p&gt;
&lt;p&gt;Please find attached PDF report in that, I have created all the manually tested proof report.&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">kunal waidande </dc:creator><pubDate>Thu, 11 Sep 2025 20:58:46 -0000</pubDate><guid>https://sourceforge.net6711227a8e7f922699d605b24f1b8fc0139346e6</guid></item><item><title>Found Vulnerability:- IDOR (Insecure Direct Object Reference)</title><link>https://sourceforge.net/p/jedit/bugs/4147/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Ticket 4147 has been modified: Found Vulnerability:- IDOR (Insecure Direct Object Reference)&lt;br/&gt;
Edited By: Eric Le Lay (kerik-sf)&lt;br/&gt;
Status updated: 'open' =&amp;gt; 'open-invalid'&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">kunal waidande </dc:creator><pubDate>Thu, 11 Sep 2025 20:58:46 -0000</pubDate><guid>https://sourceforge.netdcd3bdf2652800254048732d2cc3584e5e3d45c9</guid></item><item><title>Found Vulnerability:- IDOR (Insecure Direct Object Reference)</title><link>https://sourceforge.net/p/jedit/bugs/4147/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Ticket 4147 has been modified: Found Vulnerability:- IDOR (Insecure Direct Object Reference)&lt;br/&gt;
Edited By: Eric Le Lay (kerik-sf)&lt;br/&gt;
_milestone updated: 'severe bug' =&amp;gt; 'UNUSED'&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">kunal waidande </dc:creator><pubDate>Thu, 11 Sep 2025 20:58:46 -0000</pubDate><guid>https://sourceforge.netfce28c7fbc11e6af3a2780dae95af3e821fa0d03</guid></item></channel></rss>