Hashnode / Hashnode/support

Follow-up Regarding Submitted RCE Vulnerability Report

オープン
#101 コメント 2 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
JavaScript
スター
48
フォーク
48
PR マージ指標
30日以内にマージされた PR はありません

説明

Hello Security Team,

I hope you are doing well.

I am writing to follow up on the Remote Code Execution (RCE) vulnerability report that I recently submitted. I have already shared the relevant details and proof of concept through email and wanted to confirm that the report has been received and is currently under review.

As the vulnerability may have a significant security impact, I would appreciate any update regarding its assessment status. If the report is determined to be valid and falls within your vulnerability disclosure or bug bounty program, I would be grateful if you could consider it for a bounty reward.

Please let me know if any additional information, clarification, or testing details are required from my side. I am happy to assist further to help validate and remediate the issue.

Thank you for your time and consideration. I look forward to your response.

Best regards,
MD Mehedi Hasan (Security Talent)

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

レポートの詳細と proof of concept はメールで共有されており、この issue には調査対象となるリポジトリファイル、テスト、エントリーポイントがありません。まず元のセキュリティレポートとそのメールスレッドを確認してください。完了は、セキュリティチームによる評価、検証、修正プロセスに左右されます。

索引モデルが issue の本文から書いたものです。

評価

領域
security
issue の種類
バグ
難易度
5/5
見積もり時間
1週間以上
活発さ
静か
明瞭さ
説明が足りない
初心者へのやさしさ
10/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。