Skip to content

Requesting a private channel for a credential-disclosure issue in the default configuration #17079

Description

@router0mail

I have a vulnerability in Jackett to report and would rather not do it in a public issue, because it discloses stored third-party credentials and there is a working reproduction.

Private vulnerability reporting is not enabled on this repository (/repos/Jackett/Jackett/private-vulnerability-reporting returns enabled: false) and there is no SECURITY.md, so I could not find a private channel to use.

Could you either enable GitHub's private vulnerability reporting — Settings, Advanced Security, "Private vulnerability reporting" — or point me at an address to send it to? I will send the full write-up there.

What I can say without giving it away: it concerns the default configuration on Linux, an unauthenticated request, and a stored credential that is encrypted on disk but not in the response. Reproduced end to end against v0.24.2644.0 in a default container, with request and response captured, and with a negative control.

Happy to wait as long as you need once I have somewhere to send it.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions