google / sagetv

SageTV is a cross-platform networked DVR and media management system
http://forums.sagetv.com/
Apache License 2.0
265 stars 174 forks source link

Please open a security advisory #447

Closed JLLeitschuh closed 3 years ago

JLLeitschuh commented 3 years ago

I believe I may have found what looks like a security vulnerability in sagetv.

Please open a security advisory so we can discuss privately. https://github.com/google/sagetv/security/advisories

Narflex commented 3 years ago

I think you need to open the advisory yourself, and then it will become visible to me.

JLLeitschuh commented 3 years ago

I can't. An admin on the repository needs to do it.

Narflex commented 3 years ago

OK, opened one (let me know if you can't find it, I'm not sure if the link is obfuscated so I shouldn't post it here)

JLLeitschuh commented 3 years ago

Got it, you can post links in the public. The contents of advisories is private and only accessible to those who are added to the advisory.