Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: 'good description' as bullets

...

Write a good description

Ideally a description provides enough information for an operator to has 4 components:

  • describe whether the issue can be exploited only by authenticated attackers, or by any unauthenticated attacker
  • describe how an operator can determine whether they're affected

...

  • describe the impact is of a successful attack,

...

  • recommend what mitigations or fixes they can apply.

While it 's is OK to err on the side of transparency (after all, all the code is open anyway), we typically don't make it too easy for attackers by providing exploitation details.

...