Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Sandbox breakout #363

Closed
vdata1 opened this issue Sep 7, 2021 · 4 comments
Closed

Sandbox breakout #363

vdata1 opened this issue Sep 7, 2021 · 4 comments

Comments

@vdata1
Copy link

vdata1 commented Sep 7, 2021

Hi,

I would like to report a sandbox breakout, but I believe this should be done in a responsible, private way. Please create a security policy and an advisory, as instructed here: #338

@XmiliaH
Copy link
Collaborator

XmiliaH commented Oct 12, 2021

Sorry, I can't create advisories. Could you test if the newest version still has the breakout?

@cristianstaicu
Copy link

Hey XmiliaH, we confirm that the two breakouts we found are fixed in the last release published two days ago: the dynamic import one and the custom stack trace one. If you do not issue advisories for this project, how do you plan to acknowledge the effort we put into finding these vulnerabilities? We will not proceed to disclose the remaining one(s) until we hear a clear statement from your side about this.

@XmiliaH
Copy link
Collaborator

XmiliaH commented Oct 14, 2021

It seems that I do not have the permissions to create security advisories for this project. I suspect only @patriksimek is able to create them. If there are other ways to create advisories you can let me know.

@cristianstaicu
Copy link

I see, sorry for the misunderstanding, then. There was some miscommunication between us, the Snyk team, and you guys (we were not aware of this ticket: #366). Multi-party vulnerability disclosure is quite complex. ;) For easier communication, we can also continue this conversation over email (https://cispa.de/de/people/c01crst), and you can close this issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants