mirror of
https://github.com/netblue30/firejail.git
synced 2026-05-15 14:16:14 -06:00
[GH-ISSUE #5139] Trying to get in contact for a security report #2891
Labels
No labels
LTS merge
LTS merge
bug
bug
converted-to-discussion
doc-todo
documentation
duplicate
enhancement
file-transfer
firecfg
firejail-in-firejail
firetools
graphics
help wanted
information_old
installation
invalid
modif
moved
needinfo
networking
notabug
notourbug
old-version
overlayfs
packaging
profile-request
pull-request
question
question_old
removal
runtime-permissions
sandbox-ipc
security
stale
wiki
wiki
wontfix
wordpress
workaround
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: github-starred/firejail#2891
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @mgerstner on GitHub (May 12, 2022).
Original GitHub issue: https://github.com/netblue30/firejail/issues/5139
Originally assigned to: @netblue30 on GitHub.
We have sent multiple e-mails to netblue30@protonmail.com for reporting a vulnerability in Firejail. The first one including the full report was sent on May 3rd. We did not receive back any reply yet. Please get in contact with us about how to continue the disclosure procedure.
If we do not hear back until 2022-05-17 then we will publish the issue without further notice.
Thanks!
@kmk3 commented on GitHub (May 12, 2022):
Cc: @netblue30
@rusty-snake commented on GitHub (May 12, 2022):
IDK what kind of vulnerability it is but if there is still a need to develop a patch you can also contact on of the other developers like @smitsohu, @topimiettinen, @reinerh or me (email: take from
git logor<snip>). However release coordination (i.e. write access to firejail.wordprees.com) has only @netblue30.@netblue30 any progress with my report?
@kmk3 commented on GitHub (May 12, 2022):
(Offtopic)
@rusty-snake commented on May 12:
To be fair, I myself am not sure how I'd accomplish that given only the git
log, as your commits (and the commits of a handful of other committers) have an
"@users.noreply.github.com" email address listed. And considering that it has
"noreply" on it, I would assume that sending emails to it does not work.
@rusty-snake commented on GitHub (May 12, 2022):
I meand for the other I listed, they all have a email in firejails
git log(but IDK if this address is outdated or not). For myself I know that I use githubs-noreply, that's why I listed my.@ghost commented on GitHub (May 12, 2022):
(Offtopic)
Personally I can see how all this could be confusing for people that want to report security issues. Currently, according to https://github.com/netblue30/firejail#security-vulnerabilities the project owner's email address is the only 'correct' one to use for such reports. That being said, I agree with @rusty-snake that several other colaborators would qualify as well. But IMO we should make that VERY transparent on that part of the README.md. Just my two cents.
@rusty-snake commented on GitHub (May 12, 2022):
OT: GitHub should just implement confidential issues. GitLab has confidential issues for years now and every full-bugtracker system like bugzilla anyway. If GH wants to provide all service for developers (Git, Code search, Wiki, Project boards, Issues, CI/CD, ...) in one place, this is a clearly missing feature.
@mgerstner commented on GitHub (May 13, 2022):
Yes a patch still needs to be developed. Also a non-trivial patch I fear.
I can of course send the details to other developers, could you please agree on a list of devs to send this to, or a single person that will take care of sharing it with the rest as needed? Thanks!
@mgerstner commented on GitHub (May 13, 2022):
I have forwarded the report to @rusty-snake 41237666+rusty-snake@users.noreply.github.com now, since I will be unavailable for some days.
@jsegitz commented on GitHub (May 13, 2022):
If this doesn't work ping me and I'll step in for @mgerstner until he's back
@rusty-snake commented on GitHub (May 13, 2022):
@jsegitz @mgerstner The github-noreply address does not work, you can use the one in https://github.com/netblue30/firejail/issues/5139#issuecomment-1125273884. Also if the patch is non-trivial @smitsohu has probably the best knowledge of the code-base.
@smitsohu commented on GitHub (May 16, 2022):
Could someone confirm successful email exchange?
(so we can close here)
@rusty-snake commented on GitHub (May 16, 2022):
Yes, received.
I will forward it to you later unless someone says no.