-
-
Notifications
You must be signed in to change notification settings - Fork 3.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Found potential security vulnerability but got no response #12085
Comments
Hi there, any update? |
Ok, as a collaborator i have access to it. I actually thought that this type of attack vector will be reported. I myself reported like 4 reports like this to other projects last week. I will have a thought on this on how we can patch this. |
Thanks for your response @Uzlopak, |
Hi, I'm sorry for the delay, I missed this email. I'll discuss the issue in huntr. |
Prerequisites
Issue
Hi there,
I have found a potentially high-security issue in
mongoose
. I had tried to connect Tidelift's and also through maintainers email but got no response too. I don't create a full disclosure issue there cause it could affect the users. So please get in touch with me through email [email protected] or just access the report on https://huntr.dev/bounties/055be524-9296-4b2f-b68d-6d5b810d1ddd/ (only private accessible by maintainers).Thank you.
The text was updated successfully, but these errors were encountered: