alteryx / featuretools

An open source python library for automated feature engineering
https://www.featuretools.com
BSD 3-Clause "New" or "Revised" License
7.28k stars 878 forks source link

Fix vulnerability #2718

Closed h2oa closed 6 months ago

h2oa commented 6 months ago

Hi featuretools security team,

I submitted a report of vulnerability on huntr.com. I see your product run a bug bounty program on this platform. You can connect to the huntr admin to see details of the report at https://huntr.com/bounties/684bc4d0-3c04-46d6-9076-04bb63f383d0. This pull request is a patch for this vulnerability. Because this is a dangerous vulnerability, please consider it as quickly as possible!

Best regards, @h2oa

CLAassistant commented 6 months ago

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

thehomebrewnerd commented 6 months ago

Fixed in #2723

h2oa commented 6 months ago

Hi @thehomebrewnerd ,

Can you notify to the admin of huntr.com to consider and change my report on huntr.com to valid, this will help me receive a reward commensurate with my efforts to find vulnerabilities. Thanks!

Best regards, @h2oa

thehomebrewnerd commented 6 months ago

@h2oa Thank you for identifying this issue and providing a solution. However, I do not have any involvement with huntr.com, nor does anyone at Alteryx as far as I am aware.

h2oa commented 6 months ago

Hi @thehomebrewnerd,

I also don't know how huntr.com works, I know that this open source product is running a bug bounty program on it. Can you contact them by sending a mail to https://huntr.com/contact-us? Or you can join their discord at https://discord.com/invite/WrkrrXrF4U.

Best regards, @h2oa