3 ms·
Working for a company that requires triaging critical vulnerabilities within a few days I’ll attest to how many “critical” that are mostly unexploitable due to
by tflinton 3y ago
Working for a company that requires triaging critical vulnerabilities within a few days I’ll attest to how many “critical” that are mostly unexploitable due to a variety of reasons. There has to be a better way.
- bawolff 3y agoVuln ratings are totally divorced from reality. Sometimes the super scary ones will be marked as low or medium too.
- Waterluvian 3y agoI’ve also had zealots want to introduce some pretty significant nonsense to CI for these. I enjoyed when that meant the CTO began getting emails about my products having critical vulnerabilities. Except, uh, we don’t ever use a single Django template and whatnot.
- muldvarp 3y agoI don't think summarizing the criticality of a vulnerability as a single number is possible. Many vulnerabilities really are critical, but only to some users of a software that have some feature enabled (that might be disabled by default). The best way to communicate the criticality of a vulnerability is in text.
- deleted 3y ago[deleted]
- darthwalsh 3y agoThe worst is when some build tool has a bad regex backtracking implementation leading to denial of service with bad patterns. Of course the right answer is to just keep upgrading our dependencies... so our build machine doesn't fall into an infinite loop when a hacker rewrites our build scripts?