[GH-ISSUE #5139] Trying to get in contact for a security report #2891

Closed
opened 2026-05-05 09:33:15 -06:00 by gitea-mirror · 12 comments
Owner

Originally created by @mgerstner on GitHub (May 12, 2022).
Original GitHub issue: https://github.com/netblue30/firejail/issues/5139

Originally assigned to: @netblue30 on GitHub.

We have sent multiple e-mails to netblue30@protonmail.com for reporting a vulnerability in Firejail. The first one including the full report was sent on May 3rd. We did not receive back any reply yet. Please get in contact with us about how to continue the disclosure procedure.

If we do not hear back until 2022-05-17 then we will publish the issue without further notice.

Thanks!

Originally created by @mgerstner on GitHub (May 12, 2022). Original GitHub issue: https://github.com/netblue30/firejail/issues/5139 Originally assigned to: @netblue30 on GitHub. We have sent multiple e-mails to netblue30@protonmail.com for reporting a vulnerability in Firejail. The first one including the full report was sent on May 3rd. We did not receive back any reply yet. Please get in contact with us about how to continue the disclosure procedure. If we do not hear back until 2022-05-17 then we will publish the issue without further notice. Thanks!
gitea-mirror 2026-05-05 09:33:15 -06:00
  • closed this issue
  • added the
    security
    label
Author
Owner

@kmk3 commented on GitHub (May 12, 2022):

Cc: @netblue30

<!-- gh-comment-id:1124859830 --> @kmk3 commented on GitHub (May 12, 2022): Cc: @netblue30
Author
Owner

@rusty-snake commented on GitHub (May 12, 2022):

IDK what kind of vulnerability it is but if there is still a need to develop a patch you can also contact on of the other developers like @smitsohu, @topimiettinen, @reinerh or me (email: take from git log or <snip>). However release coordination (i.e. write access to firejail.wordprees.com) has only @netblue30.


@netblue30 any progress with my report?

<!-- gh-comment-id:1125273884 --> @rusty-snake commented on GitHub (May 12, 2022): IDK what kind of vulnerability it is but if there is still a need to develop a patch you can also contact on of the other developers like @smitsohu, @topimiettinen, @reinerh or me (email: take from `git log` or `<snip>`). However release coordination (i.e. write access to firejail.wordprees.com) has only @netblue30. --- @netblue30 any progress with my report?
Author
Owner

@kmk3 commented on GitHub (May 12, 2022):

(Offtopic)

@rusty-snake commented on May 12:

you can also contact on of the other developers [or me] (email: take from
git log

To be fair, I myself am not sure how I'd accomplish that given only the git
log, as your commits (and the commits of a handful of other committers) have an
"@users.noreply.github.com" email address listed. And considering that it has
"noreply" on it, I would assume that sending emails to it does not work.

<!-- gh-comment-id:1125306374 --> @kmk3 commented on GitHub (May 12, 2022): (Offtopic) @rusty-snake commented [on May 12](https://github.com/netblue30/firejail/issues/5139#issuecomment-1125273884): > you can also contact on of the other developers [or me] (email: take from > `git log` To be fair, I myself am not sure how I'd accomplish that given only the git log, as your commits (and the commits of a handful of other committers) have an "@users.noreply.github.com" email address listed. And considering that it has "noreply" on it, I would assume that sending emails to it does not work.
Author
Owner

@rusty-snake commented on GitHub (May 12, 2022):

I meand for the other I listed, they all have a email in firejails git log (but IDK if this address is outdated or not). For myself I know that I use githubs-noreply, that's why I listed my.

<!-- gh-comment-id:1125314501 --> @rusty-snake commented on GitHub (May 12, 2022): I meand for the other I listed, they all have a email in firejails `git log` (but IDK if this address is outdated or not). For myself I know that I use githubs-noreply, that's why I listed my.
Author
Owner

@ghost commented on GitHub (May 12, 2022):

(Offtopic)

Personally I can see how all this could be confusing for people that want to report security issues. Currently, according to https://github.com/netblue30/firejail#security-vulnerabilities the project owner's email address is the only 'correct' one to use for such reports. That being said, I agree with @rusty-snake that several other colaborators would qualify as well. But IMO we should make that VERY transparent on that part of the README.md. Just my two cents.

<!-- gh-comment-id:1125321880 --> @ghost commented on GitHub (May 12, 2022): (Offtopic) Personally I can see how all this could be confusing for people that want to report security issues. Currently, according to https://github.com/netblue30/firejail#security-vulnerabilities the project owner's email address is the only 'correct' one to use for such reports. That being said, I agree with @rusty-snake that several other colaborators would qualify as well. But IMO we should make that VERY transparent on that part of the README.md. Just my two cents.
Author
Owner

@rusty-snake commented on GitHub (May 12, 2022):

OT: GitHub should just implement confidential issues. GitLab has confidential issues for years now and every full-bugtracker system like bugzilla anyway. If GH wants to provide all service for developers (Git, Code search, Wiki, Project boards, Issues, CI/CD, ...) in one place, this is a clearly missing feature.

<!-- gh-comment-id:1125327140 --> @rusty-snake commented on GitHub (May 12, 2022): OT: GitHub should just implement confidential issues. GitLab has confidential issues for years now and every full-bugtracker system like bugzilla anyway. If GH wants to provide all service for developers (Git, Code search, Wiki, Project boards, Issues, CI/CD, ...) in one place, this is a clearly missing feature.
Author
Owner

@mgerstner commented on GitHub (May 13, 2022):

Yes a patch still needs to be developed. Also a non-trivial patch I fear.

I can of course send the details to other developers, could you please agree on a list of devs to send this to, or a single person that will take care of sharing it with the rest as needed? Thanks!

<!-- gh-comment-id:1125801845 --> @mgerstner commented on GitHub (May 13, 2022): Yes a patch still needs to be developed. Also a non-trivial patch I fear. I can of course send the details to other developers, could you please agree on a list of devs to send this to, or a single person that will take care of sharing it with the rest as needed? Thanks!
Author
Owner

@mgerstner commented on GitHub (May 13, 2022):

I have forwarded the report to @rusty-snake 41237666+rusty-snake@users.noreply.github.com now, since I will be unavailable for some days.

<!-- gh-comment-id:1126025270 --> @mgerstner commented on GitHub (May 13, 2022): I have forwarded the report to @rusty-snake 41237666+rusty-snake@users.noreply.github.com now, since I will be unavailable for some days.
Author
Owner

@jsegitz commented on GitHub (May 13, 2022):

If this doesn't work ping me and I'll step in for @mgerstner until he's back

<!-- gh-comment-id:1126029803 --> @jsegitz commented on GitHub (May 13, 2022): If this doesn't work ping me and I'll step in for @mgerstner until he's back
Author
Owner

@rusty-snake commented on GitHub (May 13, 2022):

@jsegitz @mgerstner The github-noreply address does not work, you can use the one in https://github.com/netblue30/firejail/issues/5139#issuecomment-1125273884. Also if the patch is non-trivial @smitsohu has probably the best knowledge of the code-base.

<!-- gh-comment-id:1126183474 --> @rusty-snake commented on GitHub (May 13, 2022): @jsegitz @mgerstner The github-noreply address does not work, you can use the one in https://github.com/netblue30/firejail/issues/5139#issuecomment-1125273884. Also if the patch is non-trivial @smitsohu has probably the best knowledge of the code-base.
Author
Owner

@smitsohu commented on GitHub (May 16, 2022):

Could someone confirm successful email exchange?

(so we can close here)

<!-- gh-comment-id:1127694998 --> @smitsohu commented on GitHub (May 16, 2022): Could someone confirm successful email exchange? (so we can close here)
Author
Owner

@rusty-snake commented on GitHub (May 16, 2022):

Yes, received.

I will forward it to you later unless someone says no.

<!-- gh-comment-id:1127818444 --> @rusty-snake commented on GitHub (May 16, 2022): Yes, received. I will forward it to you later unless someone says no.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: github-starred/firejail#2891
No description provided.