cactus / go-camo

A secure image proxy server
MIT License
254 stars 48 forks source link

Content-Type validation bypass (née Responsible Disclosure) #46

Closed dappelt closed 4 years ago

dappelt commented 4 years ago

I would like to report a security vulnerability. Can you please create a Draft Security Advisory?

dropwhile commented 4 years ago

Will do. Thanks!

dropwhile commented 4 years ago

Draft advisory created, and @dappelt invited to collaborate on it.

dropwhile commented 4 years ago

This advisory has been accepted. Status: Working on a fix.

dropwhile commented 4 years ago

Status: release with fix planned for tomorrow.

dropwhile commented 4 years ago

v2.1.1 released with fixes.

dropwhile commented 4 years ago

Advisory published: https://github.com/cactus/go-camo/security/advisories/GHSA-jg2r-qf99-4wvr Please upgrade your installs!

dropwhile commented 4 years ago

Thanks to @dappelt for the report, and assistance with the fix review.

dappelt commented 4 years ago

Thanks for dealing with the issue so quickly.