Skip to content

Found a possible security concern #1409

Description

@JamieSlome

Hey there!

I belong to an open source security research community, and a member (@theWorstComrade) has found an issue, but doesn’t know the best way to disclose it.

If not a hassle, might you kindly add a SECURITY.md file with an email, or another contact method? GitHub recommends this best practice to ensure security issues are responsibly disclosed, and it would serve as a simple instruction for security researchers in the future.

Thank you for your consideration, and I look forward to hearing from you!

(cc @huntr-helper)

Activity

  1. Byron commented on Feb 12, 2022

    @Byron
    Member

    Thanks a lot for looking into GitPython!

    According to the recommendation, I have added a SECURITY.md file that should help @theWorstComrade to reach out.

    We can use this ticket to track the overall progress on resolving the issue.

    And yes, I am very curious what that could be, can't wait to hear about the issue.

  2. JamieSlome commented on Feb 12, 2022

    @JamieSlome
    Author

    Hey @Byron - thanks for your response. You should have received an e-mail from us about 1 hour ago!

    You can use the magic URL in our e-mail to view the report or you can see the report directly here:
    https://huntr.dev/bounties/8549d81f-dc45-4af7-9f2a-2d70752d8524

    It is private and only accessible to maintainers with repository write permissions!

  3. Byron commented on Feb 14, 2022

    @Byron
    Member

    After giving it a shot myself, I failed to fix it without breaking tests. It probably needs more work than I am able to commit right now, or somebody more familiar with the matter at hand.

  4. JamieSlome commented on Feb 14, 2022

    @JamieSlome
    Author

    @theWorstComrade - would you be able to support with a fix?

  5. added this to the v3.1.27 - Bugfixes milestone on Feb 21, 2022
  6. Byron commented on Feb 21, 2022

    @Byron
    Member

    A fix landed with the release of 3.1.27, resolving this issue. Thanks everyone for the initiative and support.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions