Dear Security Team,

The beets web ui is very limited in its functions, it is not fit for external
publication, number of users is probably very limited to begin with, attacks
would be very unpractical.

Therefore I think this is a very low risk vulnerability.

I propose we contact upstream for a fix and backport this into the
(old-)*stable distributions without treating this with special urgency.

Do you agree with my assessment and proposed actions?

@Alto angelo, would you like to contact upstream at their github repo
https://github.com/beetbox/beets ?

Best regards,

Pieter

Attachment: signature.asc
Description: PGP signature

Reply via email to