Skip to content

Why were the patch versions for CVE-2022-25850 released so late? #72

Answered by SamJakob
Silence-worker-02 asked this question in Q&A
Discussion options

You must be logged in to vote

Hi,

First, I’ll provide some comments on the CVE itself and the processes we went through to mitigate it:

I, the author and primary maintainer, had been hosting the proxy in a jailed environment so this issue was not evident to me — as on my systems it had no access to internal services like it did when it was moved to the Hoppscotch systems. As the Hoppscotch systems were cloud infrastructure (the XSRF manifested itself in the ability for an end user to access the maintenance URL for the cloud server account).

I therefore had not discovered this issue because when I conducted my own audit, I had not been looking for issues of this nature having (perhaps erroneously) assumed that the prox…

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@Silence-worker-02
Comment options

Answer selected by SamJakob
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants