CVE posting, but like, going on a tangent
And while looking at stuff I realized that the list of GHSAs is also just visible so.…
CVE posting, but like, going on a tangent
This is the 2024 edition of "I posted the private key in chat"
CVE posting, but like, going on a tangent
Okay, so with Magento, Shopware, Drupal, Typo3, PrestaShop, Symfony, and Laravel I feel like you could've had a lot of fun the past two months. The only eCommerce platform I didn't see is OXID (which didn't have any CVEs since 2023 it seems). But yeah, that should've hit a lot of stuff.
CVE posting, but like, going on a tangent
This is so funny to me: https://github.com/advisories?query=severity%3Acritical+type%3Areviewed+jwt+none
And that's only the critical ones, there is more under high it seems.
CVE posting, but like, going on a tangent
ahhhh, yes.…
At this point I'm just laughing at everything I find.…
CVE posting, but like, going on a tangent
tasty PBKDF2 with a single iteration
CVE posting, but like, going on a tangent
CVE posting, but like, going on a tangent
@benaryorg FWIW, I'm on gbit fiber, and at first I thought the demo was broken - it barely rendered any observable latency for me