Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

🚨 Potential Security Vulnerability #555

Closed
ranjit-git opened this issue May 23, 2021 · 10 comments
Closed

🚨 Potential Security Vulnerability #555

ranjit-git opened this issue May 23, 2021 · 10 comments
Labels

Comments

@ranjit-git
Copy link

Hello, @prasathmani - 5 potential high severity security vulnerability in your repository has been disclosed to huntr.

Visit report url and validate them
https://www.huntr.dev/bounties/6-other-prasathmani/tinyfilemanager/
https://www.huntr.dev/bounties/7-other-prasathmani/tinyfilemanager/
https://www.huntr.dev/bounties/8-other-prasathmani/tinyfilemanager/
https://www.huntr.dev/bounties/9-other-prasathmani/tinyfilemanager/
https://www.huntr.dev/bounties/10-other-prasathmani/tinyfilemanager/

@zer0h-bb
Copy link

Hi @prasathmani, two other vulnerabilities were found in your repo, please check :

@x3rz
Copy link

x3rz commented May 30, 2021

Hello @prasathmani, one more vulnerability was found in your code, visit and do check it.
https://www.huntr.dev/bounties/11-other-prasathmani/tinyfilemanager/

@ranjit-git
Copy link
Author

Hello, i see it has been 6 month since bug reported and still many of them are not validated .
As fix taking long time so you can validate the report now and when patch is ready then you can confirm the fix also .
Huntr team did not proccessed the bounty to reporter untill it validated.
We invest our time to secure opensource project and report potential security vulnerability to huntr responsively .
If maintainer validate them then reporter gets bounty and it will encourage us to make opensource project a safer place .
Thanks

@michael-milette
Copy link
Contributor

Have the security issues reported in CVE-2021-40965 5 months ago been addressed yet?

For more information, please see: https://www.cvedetails.com/cve/CVE-2021-40965/

@prasathmani
Copy link
Owner

not actively contributing now, will fix all this in future release

@prasathmani
Copy link
Owner

fix to path traversal vulnerability #718. by @joaogmauricio

@ranjit-git
Copy link
Author

Hello, @prasathmani - 5 potential high severity security vulnerability in your repository has been disclosed to huntr.

Visit report url and validate them https://www.huntr.dev/bounties/6-other-prasathmani/tinyfilemanager/ https://www.huntr.dev/bounties/7-other-prasathmani/tinyfilemanager/ https://www.huntr.dev/bounties/8-other-prasathmani/tinyfilemanager/ https://www.huntr.dev/bounties/9-other-prasathmani/tinyfilemanager/ https://www.huntr.dev/bounties/10-other-prasathmani/tinyfilemanager/

@prasathmani
Can you plz validate/invalidate those report in huntr so that huntr can give bounty?

@x3rz
Copy link

x3rz commented Feb 12, 2022

Not only these but all mentioned report
thanks

@prasathmani
Copy link
Owner

This issue is addressed in the new release.

@michael-milette
Copy link
Contributor

Thank you @prasathmani !

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

5 participants