mirror of
https://github.com/HaschekSolutions/pictshare.git
synced 2026-04-26 15:35:51 +03:00
[GH-ISSUE #127] Potential Security Issues #102
Labels
No labels
Feature request
Feature request
bug
cant reproduce
enhancement
help wanted
pull-request
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/pictshare#102
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @JamieSlome on GitHub (Jun 8, 2021).
Original GitHub issue: https://github.com/HaschekSolutions/pictshare/issues/127
Hello,
I'm just getting in touch as we recently received some disclosures against this repository through our disclosure program. I tried looking for a contactable e-mail and security policy to send the details to, but could not find either.
You can find the details for the disclosures here:
https://huntr.dev/bounties/1-HaschekSolutions/pictshare/
https://huntr.dev/bounties/2-HaschekSolutions/pictshare/
https://huntr.dev/bounties/3-HaschekSolutions/pictshare/
https://huntr.dev/bounties/4-HaschekSolutions/pictshare/
They are private to yourself and the reporter. If you would prefer not to sign-up to view the disclosures, let me know, and I will be happy to share them with you over some other means.
Let me know if you have any questions.
-- Jamie from huntr.dev
@geek-at commented on GitHub (Jun 8, 2021):
Hey Jamie!
Awesome thanks. Do you have any PR for resolving these problems?
@JamieSlome commented on GitHub (Jun 8, 2021):
@geek-at - we can open up this advisory to our users once we validate it, and we can begin sourcing fixes for it. Otherwise, you can always check with the discloser to see if they have anything in mind.
@zer0h-bb commented on GitHub (Jun 10, 2021):
Hi @geek-at, I reported the two first bugs
https://huntr.dev/bounties/1-HaschekSolutions/pictshare/
https://huntr.dev/bounties/2-HaschekSolutions/pictshare/
Is it possible to validate them directly in huntr.dev ? So we can get paid and gain the associated xp :)
Best regards,
zer0h
@Blisk commented on GitHub (Sep 30, 2021):
So is it safe to use this on my server or not?
@geek-at commented on GitHub (Sep 30, 2021):
Yes. All reported vulnerabilities are only working if you don't follow the configuration. Mainly this part
If you're using the docker image you're safe out of the box
@Blisk commented on GitHub (Sep 30, 2021):
I dont use docker