Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update on Vulnerability Report #1128

Closed
AkshayraviC09YC47 opened this issue Jan 27, 2023 · 5 comments
Closed

Update on Vulnerability Report #1128

AkshayraviC09YC47 opened this issue Jan 27, 2023 · 5 comments
Labels

Comments

@AkshayraviC09YC47
Copy link

Hello maintainer,

Few months ago i have submitted a vulnerability report via huntr.dev any update on that?

Here is the report link:
https://huntr.dev/bounties/3519b110-33db-4c1a-b720-0627dc14a4c6/

@zorun zorun added the security label Jan 31, 2023
@zorun
Copy link
Collaborator

zorun commented Jan 31, 2023

@Glandos does that ring a bell?

@zorun
Copy link
Collaborator

zorun commented Jul 13, 2023

Ping @Glandos ? The page is private. Did we fix this already?

@Glandos
Copy link
Member

Glandos commented Jul 14, 2023

Yep, it's about a template injection, but it's unclear for me if it's valid. I commented on the huntr page.

By the way, if you log in via GitHub on Huntr, you should be able to access the page as a member.

@almet
Copy link
Member

almet commented Apr 28, 2024

This is indeed not a security problem, and there is no template injection here. Closing.

@almet almet closed this as completed Apr 28, 2024
@zorun
Copy link
Collaborator

zorun commented Apr 28, 2024

Indeed, both the report and the suggested patch are bogus. The apparent "injection" is not actually an injection, it merely shows that the projet ID is derived from the projet name.

Btw, the huntr link seems to be public now.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

4 participants