cachethq / cachet

🚦 The open-source status page system.
https://cachethq.io
MIT License
13.79k stars 1.55k forks source link

cachet vulnerable for CVE-2013-3587 (BREACH vulnerability in compressed HTTPS) #4045

Closed mariovitale1979 closed 3 years ago

mariovitale1979 commented 4 years ago

We did a security scan of cachet v2.4 and found out that cachet is vulnerable for CVE-2013-3587 (BREACH vulnerability in compressed HTTPS)

welcome[bot] commented 4 years ago

:wave: Thank you for opening your first issue. I'm just an automated bot that's here to help you get the information you need quicker, so please ignore this message if it doesn't apply to your issue. If you're looking for support, you should try the Slack group by registering your email address at https://cachethq-slack.herokuapp.com. Alternatively, email support@alt-three.com for our Professional support service (please note, this a paid service.) If you're issue is with documentation, you can suggest edits by clicking the Suggest Edits link on any page, or open an issue at https://github.com/CachetHQ/Docs