Hi Hauke,
I send this mail to the public mailing list because I want such a discussion. I do not think these are big problems we have to manage in private and then release in a coordinated way.
> [...]
I agree, such "low impact" report can be published right away and fixed on the next occasion, basically handle them like an ordinary issue report.
The disclosure / CVE request flow etc. should be reserved for high impact issues like unauthenticated code injection or similar.
Regards, Jo _______________________________________________ openwrt-devel mailing list [email protected] https://lists.openwrt.org/mailman/listinfo/openwrt-devel
