jaesivsm / JARR

JARR is a web news aggregator.
https://app.jarr.info
GNU Affero General Public License v3.0
118 stars 15 forks source link

Found a possible security concern #202

Open JamieSlome opened 2 years ago

JamieSlome commented 2 years ago

Hello 👋

I run a security community that finds and fixes vulnerabilities in OSS. A researcher (@saharshtapi) has found a potential issue, which I would be eager to share with you.

Could you add a SECURITY.md file with an e-mail address for me to send further details to? GitHub recommends a security policy to ensure issues are responsibly disclosed, and it would help direct researchers in the future.

Looking forward to hearing from you 👍

(cc @huntr-helper)

saharshtapi commented 2 years ago

Thanks @jaesivsm!! @JamieSlome can you please provide the further steps to access the reports.

JamieSlome commented 2 years ago

@saharshtapi - @jaesivsm should shortly receive e-mails with access to all of the reports.

JamieSlome commented 2 years ago

@saharshtapi, also feel free to share the report URLs here too 👍

saharshtapi commented 2 years ago

@jaesivsm you can access the reports from the below URLs https://huntr.dev/bounties/b19e64ec-a1f9-42f3-8f76-0acab7d438d0/ https://huntr.dev/bounties/212dbc5c-c331-47cf-b0f6-9c16defea149/ https://huntr.dev/bounties/a2ed7a0b-e272-4afd-8c7c-eb0865712a45/ https://huntr.dev/bounties/b687146d-eab3-4b71-94b4-2d9dacf226b5/ https://huntr.dev/bounties/19cefc2b-d520-4c51-9073-33db0e9afff9/ https://huntr.dev/bounties/f3e39cbe-d514-45ae-a2dc-e31b9b5a66bf/