Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Contact Requested #13

Closed
prodigysml opened this issue Jan 6, 2020 · 4 comments
Closed

Security Contact Requested #13

prodigysml opened this issue Jan 6, 2020 · 4 comments

Comments

@prodigysml
Copy link

@n33dle and I found a security vulnerability within the mercury project. We were hoping to get a core maintainer's contact details to responsibly disclose this vulnerability.

@ericcwlaw
Copy link
Collaborator

thanks for your message. This issue is closed due to lack of specific details.

@n33dle
Copy link

n33dle commented Jan 6, 2020

Hi @ericcwlaw - we're after some contact details to responsibly disclose a security vulnerability within this mercury project.

@ericcwlaw
Copy link
Collaborator

@n33dle @prodigysml Thank you so much for pointing out the Xml External Entity (XXE) security vulnerability and providing your recommendation. We have patched the SimpleXmlParser and finished regression tests. The patch will be added to the release v1.12.28.

@ericcwlaw ericcwlaw reopened this Jan 8, 2020
@ericcwlaw
Copy link
Collaborator

code merged and verified

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants