oss-sec mailing list archives

Re: Ruby gem rack-mini-profiler CVE-2016-4442


From: Reed Loden <reed () reedloden com>
Date: Fri, 10 Jun 2016 09:23:50 +0200

On Fri, Jun 10, 2016 at 8:10 AM, Sam Saffron <sam.saffron () gmail com> wrote:


I am not sure how to go about announcing this CVE, where else to I
need to post this?


This is actually somewhat documented, believe it or not!

http://guides.rubygems.org/security/#reporting-security-vulnerabilities

Yay for documentation! Though, boo for it needing to be updated since OSVDB
is gone now. :(

~reed

Current thread: