nginx-proxy-manager icon indicating copy to clipboard operation
nginx-proxy-manager copied to clipboard

Trying to get in touch regarding a security issue

Open JamieSlome opened this issue 3 years ago • 14 comments

Hello 👋

I run a security community that finds and fixes vulnerabilities in OSS. A researcher (@dwisiswant0) has found a potential issue, which I would be eager to share with you.

Could you add a SECURITY.md file with an e-mail address for me to send further details to? GitHub recommends a security policy to ensure issues are responsibly disclosed, and it would help direct researchers in the future.

Looking forward to hearing from you 👍

(cc @huntr-helper)

JamieSlome avatar May 21 '22 00:05 JamieSlome

Would you like to come take a look at it, @jc21? Your prompt attention would be appreciated. :)

dwisiswant0 avatar May 22 '22 17:05 dwisiswant0

Any update on this? I would also like to report something and would appreciate an email or way to privately contact the developers.

Legoclones avatar Oct 31 '22 21:10 Legoclones

^ Nope. Committed 11 days ago on the develop branch, I think the maintainers like to play dead.

dwisiswant0 avatar Oct 31 '22 23:10 dwisiswant0

How is it that something important like this goes unanswered for almost seven months while commits take place in between?

@jc21

sephentos avatar Nov 23 '22 00:11 sephentos

Has this been rectified?

flikites avatar Nov 29 '22 06:11 flikites

Has this been rectified?

AFAIK, nope.

dwisiswant0 avatar Nov 29 '22 06:11 dwisiswant0

Any news on this one? Did @jc21 get in contact with you guys?

Joly0 avatar Jan 20 '23 22:01 Joly0

No.

dwisiswant0 avatar Jan 21 '23 06:01 dwisiswant0

This is the issue, the advisory is out now: https://advisory.dw1.io/57

liquidat avatar Feb 18 '23 23:02 liquidat

@skarlcf this issue should be closed since it's been resolved by #2635, unless I missed something. I just stumbled upon this.

BrutalCoding avatar Jan 23 '24 15:01 BrutalCoding

@BrutalCoding yes, IMHO this issue should be closed.

skarlcf avatar Feb 07 '24 18:02 skarlcf

Issue is now considered stale. If you want to keep it open, please comment :+1:

github-actions[bot] avatar Aug 08 '24 01:08 github-actions[bot]