5 ms·
How many of you have received this notice via an official security advisory channel you're monitoring/acting on? If so, which advisory service do you use and ho
by lecha 3y ago
How many of you have received this notice via an official security advisory channel you're monitoring/acting on? If so, which advisory service do you use and how you configure it? Learning about HN is useful, but far from a reliable solution.
- xctr94 3y agoI got an email directly from Metabase.
- Mandatum 3y agoSaw it on HN.
- deleted 3y ago[deleted]
- not_your_vase 3y agoIt is definitely not announced on Full Disclosure nor on oss-security mailing lists.
- worthless-trash 3y agoDoesn't look like there is a CVE either: https://www.cvedetails.com/vulnerability-list/vendor_id-19475/product_id-51231/year-2023/Metabase-Metabase.html https://www.cvedetails.com/vulnerability-list/vendor_id-1947...
- capableweb 3y ago> Will you release any information about the vulnerability? > Yes, we’ll be releasing the patch publicly, as well as a CVE and an explanation in two weeks. We’re delaying release to give our install base a bit of extra time before this is widely exploited. From their blog.
- ungamedplayer 3y agoOh absolutely, but its trivial to get a CVE from the relevant CNA's. A webform or a phone call. Its a bit silly.
- capableweb 3y agoDon't you have to share more details about the exploit then? That seems to be the thing they're trying to avoid for now.
- worthless-trash 3y agoNegative, you can request a CVE without specific details, CNA's do this all the time until unembargo.
- swe_dima 3y agoI am subsribed to their Github releases and when I saw a release for every old version I knew what's up :-)
- rudasn 3y agoYeah I do the same for projects I use. I also received an email but don't remember if I also signed up to their newsletters or something like that.