WeBWorK Main Forum

possible vulnerabilities

possible vulnerabilities

by Andras Balogh -
Number of replies: 2

Is this forum the right place to discuss and diagnose possible security vulnerabilities in webwork? 

Hopefully the red flags are just mistakes by automated security scans, but who knows.

Andras


In reply to Andras Balogh

Re: possible vulnerabilities

by Alex Jordan -

Please do consider if you have found a security vulnerability, that posting publicly about it here might direct bad actors to abuse it.

There is some discussion about what to do instead. Have a special mailing list. A Slack channel. Other things. It's not clear to me yet what will happen. In the meantime I'm not sure what to recommend.
In reply to Andras Balogh

Re: possible vulnerabilities

by Nathan Wallach -

Until there is a better solution - email one of the core team members. I'll send you some addresses to choose from.