cactus / go-camo

A secure image proxy server

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Content-Type validation bypass (née Responsible Disclosure)

dappelt opened this issue · comments

I would like to report a security vulnerability. Can you please create a Draft Security Advisory?

commented

Will do. Thanks!

commented

Draft advisory created, and @dappelt invited to collaborate on it.

commented

This advisory has been accepted.
Status: Working on a fix.

commented

Status: release with fix planned for tomorrow.

commented

v2.1.1 released with fixes.

commented

Advisory published: GHSA-jg2r-qf99-4wvr
Please upgrade your installs!

commented

Thanks to @dappelt for the report, and assistance with the fix review.

Thanks for dealing with the issue so quickly.