Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security vulnerability disclosure #67

Open
kazet opened this issue Nov 21, 2023 · 6 comments
Open

Security vulnerability disclosure #67

kazet opened this issue Nov 21, 2023 · 6 comments
Labels
enhancement New feature or request security

Comments

@kazet
Copy link

kazet commented Nov 21, 2023

Hello,

CERT PL found a security vulnerability in this repository. How can we report this privately? We don't see any security policy describing how such vulnerabilities should be reported.

@jan-vandenberg
Copy link
Owner

Please send to my personal email janvdberg at gmail

@kazet
Copy link
Author

kazet commented Nov 23, 2023

Thank you! You should have received a report.

@kazet kazet closed this as completed Nov 23, 2023
@lukigruszka
Copy link

Hello,

CERT PL has sent you a report on 23rd of November and resent it on 18th of December.
Have you received any of them?

@jan-vandenberg
Copy link
Owner

Yes, but the mentioned finding applies to core/relations.php.
This is code that is NOT meant to be deployed.

Cruddiy GENERATES code that IS meant to be deployed, and any findings there are of greater importance (not the generator code).

That being said, we will of course try and look into it, but that explains a little bit why there wasn't a direct response.

@lukigruszka
Copy link

We are aware that this code is not meant to be deployed.
However, in a limited scope that vulnerability still poses a risk - when a user runs cruddiy locally and then enters a malicious website which performs such a crafted POST request to localhost, some arbitrary shell command will be executed on his/her machine.

@lukigruszka
Copy link

Hi, any updates on that? We would like to proceed with assigning a CVE for that vulnerability

@germain-italic germain-italic added enhancement New feature or request security labels Apr 16, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request security
Projects
None yet
Development

No branches or pull requests

4 participants