4 ms·
I was the one who reported this originally in 2020. Christian said it wasn't a vulnerability because it was intended that people who used standard library funct
by ehhthing 4y ago
I was the one who reported this originally in 2020. Christian said it wasn't a vulnerability because it was intended that people who used standard library functions should validate user input. A day later I get another email saying that a CVE had been assigned, and that it was now suddenly a vulnerability.
I wait a few months, follow up and nothing. Pretty much dropped it for 2 years and now I see that they finally fixed it and never let me know. I asked a few days ago whether I'd be credited in the CVE, still no reply...
Why do I feel as if there are serious communication issues here?
- zelphirkalt 4y agoMaybe it is not in their code of conduct to let you know or reply in a timely manner.
- gpshead 4y agoBecause there are. Digging through our history, a person who reported the same thing earlier than you never got a response at all. Like I said, we've identified organizational issues to be addressed. (I honestly don't know who should be "credited" on the CVE nor do I have control over that, sorry)