careteditor / issues

Caret issues
https://caret.io
327 stars 12 forks source link

Critical security vulnerability in Caret 4.0.0-rc21 #841

Closed manuelbua closed 5 years ago

manuelbua commented 5 years ago

Hi guys, i found a critical security issue in Caret 4.0.0-rc21 and i would like to reach out to you privately so that i can give you the details without disclosing them publicly yet. Is there an email address i can write to?

astoilkov commented 5 years ago

@manuelbua Yes. You can reach out to me personally at astoilkov@caret.io. Thanks for your understanding!

manuelbua commented 4 years ago

Hi @astoilkov, this was fixed with 4.0-rc22 as of 21 November 2018 as per our mail exchange last year. I'm writing this so that it's publicly know this issue was also promptly resolved and can now request a CVE as well.

astoilkov commented 4 years ago

Great, thanks!