ryanlelek / Raneto

Markdown powered Knowledgebase Wiki for Node.js
https://raneto.com
MIT License
2.79k stars 447 forks source link

Security Issue #368

Closed J-GainSec closed 2 years ago

J-GainSec commented 2 years ago

Hi, I found three security issues within your application. I'm hoping to get in touch to disclose further details about them. If you can reach out via GitHub or security@gainsecmail.com I will share the details privately.

Thank you for your time

ryanlelek commented 2 years ago

Thank you, emailed cc @gilbitron

ryanlelek commented 2 years ago

Should be fixed in Release v0.17.1 Thank you for reporting

ryanlelek commented 2 years ago

@J-GainSec Hi there. I see the CVEs flowing into the automated reporting systems. Were you able to re-test v0.17.1 with patches? (If not that's ok)

Anything else you need or can we close this issue?

J-GainSec commented 2 years ago

I have not but I'm happy too in the upcoming week if you'd like.

I'm all good if not. You can close the issue.

Thank you for your responsiveness and professionalism.