NewsLab
Apr 28 23:41 UTC

Carrot Disclosure: Forgejo (dustri.org)

37 points|by bo0tzz||3 comments|Read full story on dustri.org

Comments (3)

3 shown
  1. 1. dangus||context
    The author's attitude is so off-putting. What gives? Did Forgejo hurt you?

    The Forgejo disclosure process looked pretty simple and straightforward to me. The bold and all-caps words that bothered the author are just making sure you know how to disclose vulnerabilities safely without leaking zero-day exploits to a wider audience than necessary.

    I'm also not impressed with a carrot disclosure that looks like this. Running a python script to compromise a locally hosted instance? Bruh, you have physical hardware and host shell access. That python script could be doing anything including running as root.

    Show us the exploit hitting a remote server.

  2. 2. unethical_ban||context
    From a linked PR (related to this RCE?), from a maintainer who closed it:

    >Just thinking something not being used is not enough, even if it's a security sensitive topic

    Linux kernel seems to disagree. This is a dangerously naive way to think of networked software in the AI age.

    ---

    edit: I got hit with the "posting too fast" block again, so I'll reply to dangus here:

    >While a remote host would further prove the claim, the person clearly claims it is RCE, not just CE. It would be quite the pie in the face if the author wrote a python script to take in an IP address but modified system files on the backend to create a stunt.

  3. 3. 000ooo000||context
    Hopefully someone a little more.. pragmatic gets eyes on that linked PR.