Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security vulnerability + preferred disclosure channel #169

Closed
obi1kenobi opened this issue Feb 4, 2016 · 6 comments
Closed

Security vulnerability + preferred disclosure channel #169

obi1kenobi opened this issue Feb 4, 2016 · 6 comments

Comments

@obi1kenobi
Copy link
Contributor

I discovered a serious security vulnerability in the client, and in the spirit of responsible disclosure, I was hoping to discuss it privately with the maintainers of this project. However, I was not able to find a contact email address of any kind for either @mogui or @Ostico , and I'm unaware of any other maintainers with admin access to the repo.

I didn't want to simply open a pull request with the fix, because that until that pull request is merged and a new version is put on pypi, it's just sitting there as a proof-of-concept exploit of a vulnerability.

I would appreciate it if one of the maintainers could reply to this issue and direct me to the preferred channel for disclosing security vulnerabilities.

@lebedov
Copy link
Contributor

lebedov commented Feb 4, 2016

Their email addresses are on the pyorient PyPI page.

@obi1kenobi
Copy link
Contributor Author

Good call. I will update this issue once the vulnerability is resolved.

@Ostico
Copy link
Collaborator

Ostico commented Feb 4, 2016

Hi @obi1kenobi ,
feel free to write me directly about that, my email is in the PyOrient package also:
https://github.com/mogui/pyorient/blob/master/setup.py#L23

@obi1kenobi
Copy link
Contributor Author

Will do. Taking this to email for now. Thanks!

@mogui
Copy link
Owner

mogui commented Feb 5, 2016

Ohai mail are available on pypi address is directly with all the details please :)

Sorry for typo, sent in mobility
Niko

On 04 Feb 2016, at 22:57, Predrag Gruevski notifications@github.com wrote:

Will do. Taking this to email. Thanks!


Reply to this email directly or view it on GitHub.

@obi1kenobi
Copy link
Contributor Author

Addressed in #172.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants