Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Security vulnerability + preferred disclosure channel #169

Closed
obi1kenobi opened this issue Feb 4, 2016 · 6 comments
Closed

Security vulnerability + preferred disclosure channel #169

obi1kenobi opened this issue Feb 4, 2016 · 6 comments

Comments

@obi1kenobi
Copy link
Contributor

I discovered a serious security vulnerability in the client, and in the spirit of responsible disclosure, I was hoping to discuss it privately with the maintainers of this project. However, I was not able to find a contact email address of any kind for either @mogui or @Ostico , and I'm unaware of any other maintainers with admin access to the repo.

I didn't want to simply open a pull request with the fix, because that until that pull request is merged and a new version is put on pypi, it's just sitting there as a proof-of-concept exploit of a vulnerability.

I would appreciate it if one of the maintainers could reply to this issue and direct me to the preferred channel for disclosing security vulnerabilities.

@lebedov
Copy link
Contributor

lebedov commented Feb 4, 2016

Their email addresses are on the pyorient PyPI page.

@obi1kenobi
Copy link
Contributor Author

Good call. I will update this issue once the vulnerability is resolved.

@Ostico
Copy link
Collaborator

Ostico commented Feb 4, 2016

Hi @obi1kenobi ,
feel free to write me directly about that, my email is in the PyOrient package also:
https://github.com/mogui/pyorient/blob/master/setup.py#L23

@obi1kenobi
Copy link
Contributor Author

Will do. Taking this to email for now. Thanks!

@mogui
Copy link
Owner

mogui commented Feb 5, 2016

Ohai mail are available on pypi address is directly with all the details please :)

Sorry for typo, sent in mobility
Niko

On 04 Feb 2016, at 22:57, Predrag Gruevski notifications@github.com wrote:

Will do. Taking this to email. Thanks!


Reply to this email directly or view it on GitHub.

@obi1kenobi
Copy link
Contributor Author

Addressed in #172.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants