forwarded 1059296 https://github.com/projecthamster/hamster/issues/750
thanks

Hi Moritz,

Thanks for bringing this to attention, this was not reported upstream
yet.

> https://github.com/BrunoTeixeira1996/CVE-2023-36250/blob/main/README.md
> sounds a little bogus, I don't see how this crosses any security boundary?

AFAICS it does not cross any boundary, but if it allows arbitrary
commands to be executed when just importing a CSV file, that would still
be unexpected and a security issue.

I haven't looked at the code yet, but hope to do so in the common days.
Let's keep further discussion about this upstream for now.

Gr.

Matthijs

Attachment: signature.asc
Description: PGP signature

Reply via email to