Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Several critical security vulnerabilities - looking for a contact #1599

Closed
rverton opened this issue Feb 7, 2018 · 14 comments
Closed

Several critical security vulnerabilities - looking for a contact #1599

rverton opened this issue Feb 7, 2018 · 14 comments

Comments

@rverton
Copy link

rverton commented Feb 7, 2018

Hi,
who can I talk to about some critical vulnerabilities I found in Trovebox?

Greetings,
robin

@cedricbonhomme
Copy link
Contributor

Hello,
I would be interested to get feedback from this.

thank you

@rverton
Copy link
Author

rverton commented Feb 9, 2018

Hi @cedricbonhomme,
I would prefer sending details of this to a core contributor. I also tried reaching @jmathai by mail but without success.
Best Regards,
robin

@jmathai
Copy link
Member

jmathai commented Feb 9, 2018

Hi @rverton, can you send it to jaisen at githubusername dot com?

@rverton
Copy link
Author

rverton commented Feb 10, 2018

Hi @jmathai,
thanks for responding. I just sent another email to this address, maybe it was marked as spam the last time.

@cedricbonhomme
Copy link
Contributor

Hi @rverton ,
it is possible to have some news? At least by email
Thanks a lot!

@rverton
Copy link
Author

rverton commented Mar 5, 2018

HI @cedricbonhomme,
I'm in contact with @jmathai and his plan is to add the vulnerabilities as issues here and/or directly fix them. Initially I planned to wait for releasing the advisory until a fix is released, but if the vulnerabilities are published as issues here I will post the advisory as soon as possible.

@cedricbonhomme
Copy link
Contributor

OK, thank you for the feedback!

@jmathai
Copy link
Member

jmathai commented Mar 6, 2018

@cedricbonhomme I forwarded you the report which @rverton shared with me.

@cedricbonhomme
Copy link
Contributor

thank you! I'll have a look at the report.

@rverton
Copy link
Author

rverton commented Mar 6, 2018

Hi @cedricbonhomme,
looks like you are working on this now, so if you have any questions, feel free to contact me directly at hello at robinverton de.

@cedricbonhomme cedricbonhomme mentioned this issue Mar 21, 2018
@cedricbonhomme
Copy link
Contributor

Hi @jmathai,
Do you will have some time soon to have a look at it (and also the PR)?
thanks,

@rverton
Copy link
Author

rverton commented Apr 4, 2018

Hi @jmathai, is there any update on this? The PR from cedric with the vulnerabilities is public, so it would be better to merge this sooner than later.
Thanks

@jmathai
Copy link
Member

jmathai commented Apr 6, 2018

Sorry for the delay --- i reviewed the pr and added some comments.

jmathai added a commit that referenced this issue Apr 26, 2018
Fix security patches reported in #1599
@rverton
Copy link
Author

rverton commented Apr 26, 2018

Hi @jmathai, @cedricbonhomme ,
thanks to both of you for your time fixing this. I'll finish and publish the advisory soon.
Bests,
Robin

@rverton rverton closed this as completed Apr 26, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants