Coder Social home page Coder Social logo

Comments (17)

timnolte avatar timnolte commented on June 5, 2024

Seems like it would be good to setup:

https://docs.github.com/en/code-security/security-advisories/working-with-repository-security-advisories/configuring-private-vulnerability-reporting-for-a-repository

from openlitespeed.

litespeedtech avatar litespeedtech commented on June 5, 2024

You can send email to bug litespeedtech com .

from openlitespeed.

Skad0sh avatar Skad0sh commented on June 5, 2024

We have send a mail with the complete PoC attached @litespeedtech

from openlitespeed.

Skad0sh avatar Skad0sh commented on June 5, 2024

we haven't recieved any replies on mail yet @litespeedtech

from openlitespeed.

litespeedtech avatar litespeedtech commented on June 5, 2024

We replied the email through our ticket system on Friday 8th March, please check your email spam folder.

Please try the latest 1.8.0 debug build see if the vulnerability has been fixed or not.
/usr/local/lsws/admin/misc/lsup.sh -b -e 1.8.0

from openlitespeed.

Skad0sh avatar Skad0sh commented on June 5, 2024

Can you confirm ? I can't find it as a reply to my mail , its not in the spam too.

from openlitespeed.

Skad0sh avatar Skad0sh commented on June 5, 2024

We have replied to your Ticket mail.

from openlitespeed.

Skad0sh avatar Skad0sh commented on June 5, 2024

The bug still exists in the current release. Please check our reply to your mail ticket bug[@]litespeedtech[.]com
Ticket ID: 293496 @litespeedtech

from openlitespeed.

litespeedtech avatar litespeedtech commented on June 5, 2024

Thanks. We will have it fixed in a different way then.

from openlitespeed.

Skad0sh avatar Skad0sh commented on June 5, 2024

The current fix seems to solve the issue , please assign a CVE to credit the researchers from the first report we send.

from openlitespeed.

Skad0sh avatar Skad0sh commented on June 5, 2024

I think this bug is already patched , any update regarding the CVE ? @litespeedtech

from openlitespeed.

kenballus avatar kenballus commented on June 5, 2024

Curious to hear what this issue is. I wonder if it overlaps with any of the request smuggling issues I noticed a few months ago that have remained unfixed. See the README here for a list of these issues: https://github.com/narfindustries/http-garden

Send me mail (address at bottom of page on my website) if you know the answer to this.

from openlitespeed.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.