Subject: Developers of Sympa
List archive
Re: [sympa-developpers] Possible sympa security issue.
- From: David Verdin <address@concealed>
- To: address@concealed
- Subject: Re: [sympa-developpers] Possible sympa security issue.
- Date: Thu, 24 Mar 2016 14:56:13 +0100
Hi Evans, sorry for this late answer - and for not fixing the su problem yet, I can't find a good way to do it. This list is a good place. We have very few subscribers and most of them are Sympa developers, so pluease feel free to post your problem - and workaround - here. cheers, David Le 17/03/2016 15:29, MDT Evans (via
sympa-developpers Mailing List) a écrit :
Apologies. It should have been:I've found an unauthenticated HTML injection into Sympa 6.1.24 (maybe in other versions). Can anyone advise on who we can report this to please. I don't really want to publicise it on this list or on the bug tracker.Also, I have a patch for a possible workaround but would like to know if there is a better approach. Thanks, Martin. --
A bug in Sympa? Quick! To the bug tracker!
|
Attachment:
smime.p7s
Description: Signature cryptographique S/MIME
-
[sympa-developpers] Possible sympa security issue.,
MDT Evans, 03/17/2016
-
Re: [sympa-developpers] Possible sympa security issue.,
MDT Evans, 03/17/2016
-
Re: [sympa-developpers] Possible sympa security issue.,
David Verdin, 03/24/2016
- Re: [sympa-developpers] Possible sympa security issue., MDT Evans, 03/24/2016
-
Re: [sympa-developpers] Possible sympa security issue.,
David Verdin, 03/24/2016
-
Re: [sympa-developpers] Possible sympa security issue.,
MDT Evans, 03/17/2016
Archive powered by MHonArc 2.6.19+.