Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Please enable private disclosures ASAP #466

Closed
Zemnmez opened this issue Oct 19, 2023 · 6 comments
Closed

Please enable private disclosures ASAP #466

Zemnmez opened this issue Oct 19, 2023 · 6 comments

Comments

@Zemnmez
Copy link

Zemnmez commented Oct 19, 2023

You can do it with the Security panel.

Please enable:

  • "Security advisories"
  • "Private vulnerability reporting"

I found a serious vulnerability in crypto-js. Please enable vulnerability disclosures so I can responsibly disclose the vulnerability. Thanks.

Twitter thread with some context: https://twitter.com/zemnmez/status/1714513369745830026

@wulinnan
Copy link

hello,I'd like to ask about this vulnerability, what exactly is it and is it easy to say, because I see that this library is supposed to be the most popular at the moment and have recently wanted to use it.

@MaksimKiselev
Copy link

MaksimKiselev commented Oct 23, 2023

@Zemnmez
Copy link
Author

Zemnmez commented Oct 23, 2023

@Zemnmez
Copy link
Author

Zemnmez commented Oct 23, 2023

hello,I'd like to ask about this vulnerability, what exactly is it and is it easy to say, because I see that this library is supposed to be the most popular at the moment and have recently wanted to use it.

I can't answer this question without doing serious damage by disclosing it when there is no patch.

@evanvosberg
Copy link
Member

@Zemnmez reporting vulnerabilities is enabled now, although the project itself is discontinued.

@Zemnmez
Copy link
Author

Zemnmez commented Oct 23, 2023

GHSA-xwcq-pm8m-c4vf

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants