Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security concern #370

Closed
JamieSlome opened this issue Aug 18, 2022 · 4 comments
Closed

Security concern #370

JamieSlome opened this issue Aug 18, 2022 · 4 comments
Labels

Comments

@JamieSlome
Copy link

JamieSlome commented Aug 18, 2022

Describe the issue

A security policy is not established for this project and it would be helpful to have an e-mail address or process that can be followed when a vulnerability has been discovered.

To Reproduce

There are no reproduction steps as this is not a bug nor a code-related issue, this is a maintenance issue.

Expected behaviour

There is no expected behaviour as this is not a bug nor a code-related issue, this is a maintenance issue.

Screenshots

Here is a screenshot of the project security policy being disabled...

Screenshot 2022-08-19 at 10 00 15

Additional context

I run a security community that finds and fixes vulnerabilities in OSS. A researcher (@Pyraun) has found a potential issue, which I would be eager to share with you.

Could you add a SECURITY.md file with an e-mail address for me to send further details to? GitHub recommends a security policy to ensure issues are responsibly disclosed, and it would help direct researchers in the future.

Looking forward to hearing from you 👍

(cc @huntr-helper)

@syoyo syoyo added the invalid label Aug 18, 2022
@syoyo syoyo closed this as completed Aug 18, 2022
@syoyo
Copy link
Owner

syoyo commented Aug 18, 2022

#291

@JamieSlome
Copy link
Author

JamieSlome commented Aug 19, 2022

@syoyo - I have updated the contents of this issue, can we re-open it?

EDIT:

Just for your reference, these are the two reports we received:

https://huntr.dev/bounties/edfa7586-d39e-4b88-b51b-338b5922bee0/
https://huntr.dev/bounties/e0771304-f3b4-4207-a7a8-c3805cc11566/

@syoyo
Copy link
Owner

syoyo commented Aug 19, 2022

You need to post minimal reproducible code and dataset if you find an issue.

example: syoyo/tinyexr#169

@JamieSlome
Copy link
Author

I see :)

Are you happy for me to share both vulnerabilities in separate GitHub Issues?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants