mealie-recipes / mealie

Mealie is a self hosted recipe manager and meal planner with a RestAPI backend and a reactive frontend application built in Vue for a pleasant user experience for the whole family. Easily add recipes into your database by providing the url and mealie will automatically import the relevant data or add a family recipe with the UI editor
https://docs.mealie.io
GNU Affero General Public License v3.0
5.66k stars 615 forks source link

[Security] Reporting of a vulnerability #3509

Open b4tb34r opened 2 months ago

b4tb34r commented 2 months ago

Hello,

together with 1Atlas1, Garfunkl and chiefmastermind I found some vulnerabilities in Mealie. (I had to link their profiles because unfortunately the tag doesn't work) According to your Security Policy we will send an email to ob92oy0sl@mozmail.com within the next few minutes.

We are looking forward to hearing from you, b4tb34r, 1Atlas1, Garfunkl, chiefmastermind

hay-kot commented 2 months ago

Hello! I got your initial email, but my email forwarder mangled the message and I don't see any contact details to respond. Could you please try sending another email to that address and include your contacts so I can reach back out? Thanks!

b4tb34r commented 2 months ago

Hi, we sent the mail again an hour ago, but now with our contact information.

hay-kot commented 2 months ago

Following up on this again. I reached out to for more specifics about the issue you're seeing and haven't heard anything back.

b4tb34r commented 2 months ago

Sorry, we had to do create a clean writedown for you and all of us had some ...life... in between (as we told you, we are a group of students and also had an exam today). We will send you the writedown tomorrow!

github-actions[bot] commented 1 month ago

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

b4tb34r commented 1 month ago

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

Just leaving a comment to avoid that this ticket is automatically closed. I hope this is ok for you.

boc-the-git commented 1 month ago

That's appreciated @b4tb34r!