DUE TO SPAM, SIGN-UP IS DISABLED. Goto Selfserve wiki signup and request an account.
...
Write a good description
Ideally a description provides enough information for an operator to has 4 components:
- describe whether the issue can be exploited only by authenticated attackers, or by any unauthenticated attacker
- describe how an operator can determine whether they're affected
...
- describe the impact is of a successful attack,
...
- recommend what mitigations or fixes they can apply.
While it 's is OK to err on the side of transparency (after all, all the code is open anyway), we typically don't make it too easy for attackers by providing exploitation details.
...