combust / combust/mleap

Security vulnerabilities in MLeap serving stack - requesting private reporting channel

Open
#897 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Scala
Stars
1.5k
Forks
315
PR merge metrics
No merged PRs in 30d

Description

Hello maintainers,

I've identified multiple security vulnerabilities in the MLeap serving modules (mleap-spring-boot, mleap-executor, mleap-grpc-server) affecting the current release (v0.24.0). These include issues that allow unauthenticated remote callers to crash the service and influence server-side network behavior.

I'd prefer to share the full details privately before any public disclosure. Could you point me to a secure reporting channel; email, GitHub private vulnerability reporting, or similar?

I've also sent details to combust@combust.ml in parallel.

Thanks,
addcontent

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.