Skip to content

Why were the patch versions for CVE-2019-13126, CVE-2020-28466 released so late? #4798

Discussion options

You must be logged in to vote

I can take this, although the first of those pre-dates my involvement with our security process.

Neither of those CVEs was for more than a denial-of-service. They needed to be fixed, but they both boil down to "someone who has already authenticated with valid credentials, can DoS the server". We don't expedite releases for such fixes and tend to not embargo.

We did later formalize our stance regarding untrusted users, in our advisory policy at https://advisories.nats.io/advisory-policy:

Those who are running services which allow untrusted users are encouraged to build regularly from git.

If you look at the history of our advisories on the https://advisories.nats.io/ website (which start…

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by philpennock
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants