3 ms·
"once they penetrate organizations." Yep, that is the key. Crashing your own org hasn't done that. Unless I'm misunderstanding what you are claiming?
by codingdave 2y ago
"once they penetrate organizations."
Yep, that is the key. Crashing your own org hasn't done that. Unless I'm misunderstanding what you are claiming?
- Max-Ganz-II 2y agoNo. It's not a way to get in, but it is a way to crash a system (which should not be crashable) if you are in.
- codingdave 2y agoI think you are describing a bug, not a vulnerability. Is it bad? Sure. Is it a security vulnerability where you can impact anyone else? Doesn't sound like it.
- Max-Ganz-II 2y agoThis makes sense and I see it, but there is one matter which gives me pause; when I came to submit the issue, there's some kind of standard severity rating system, which you have to fill in. Questions like - can this issue be exploited over a network, or do you need local access? how many privileges are required? what's the consequence of the issue - degraded service, complete denial of service? questions like this. The issue here fitted into this framework of questions - there was no point where it didn't fit, and the severity rating system was evidently thinking in different terms.