Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security exploit report #1584

Open
1 task done
matthewlordtech opened this issue Feb 6, 2025 · 2 comments
Open
1 task done

Security exploit report #1584

matthewlordtech opened this issue Feb 6, 2025 · 2 comments
Labels
bug Something isn't working

Comments

@matthewlordtech
Copy link

matthewlordtech commented Feb 6, 2025

Is there an existing issue for this?

  • I have searched the existing issues

Describe The Bug

Hi, how do I go about disclosing a security vulnerability? I’ve patched it out locally but you’ll want to fix it for everyone else. I’ve had a lot of trouble contacting author privately.

To Reproduce

No response

Expected behavior

Not relevant

Relevant log output

Not relevant

Screenshots

No response

Homebridge Ring Config

Not relevant

Additional context

No response

OS

All

Node.js Version

All

NPM Version

All

Homebridge/HOOBs Version

All

Homebridge Ring Plugin Version

All

Operating System

All

@matthewlordtech matthewlordtech added the bug Something isn't working label Feb 6, 2025
@dgreif
Copy link
Owner

dgreif commented Feb 6, 2025

@matthewlordtech I did receive your emails, but haven't had a chance to dig into a solution yet. I'll chat with @tsightler, the other maintainer, and share your concerns with him. I think the situation you outlined is very low probability and has been around for a long time, but we should be able to fix it fairly easily. I'll update this issue when we have a path forward.

@matthewlordtech
Copy link
Author

Thats great news, i'll leave it with you for now then.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants