Re: Any Update on Reported Vulnerability - Mailing list pgsql-www

From Bruce Momjian
Subject Re: Any Update on Reported Vulnerability
Date
Msg-id 20210504134112.GA27412@momjian.us
Whole thread Raw
In response to Any Update on Reported Vulnerability  (arslan.whitehat@inbox.eu)
Responses Re: Any Update on Reported Vulnerability  ("Jonathan S. Katz" <jkatz@postgresql.org>)
List pgsql-www
On Tue, May  4, 2021 at 12:50:24AM +0300, M.Arslan Kabeer wrote:
> Hi there,
> Team kindly see that this is a P4 priority 4 vulnerability from this attack an
> attacker can spam your users by send them email using your website official
> email address, I have been rewarded 300$-350$ on this same vulnerability,
> kindly some sort of reward would be much appreciated. I have found and reported
> another vulnerability a critical one, kindly take a look.

I now think we need to create a web page we can reference when people
looking for recognition/money try reporting things like this.  Obviously
this reporting has attracted many unhelpful people and an official page
might help them to ignore us.

-- 
  Bruce Momjian  <bruce@momjian.us>        https://momjian.us
  EDB                                      https://enterprisedb.com

  If only the physical world exists, free will is an illusion.




pgsql-www by date:

Previous
From: Magnus Hagander
Date:
Subject: Re: Add versions.json endpoint with latest release information
Next
From: "Jonathan S. Katz"
Date:
Subject: Re: Any Update on Reported Vulnerability