Skip to content

Comment on An update on 0day CVE-2021-43798: Grafana directory traversal

Comments

2021-12-03: Release plan set: 2021-12-07 for private customer release, 2021-12-14 for public release

Does someone know why they were playing on sitting on the public release for a week after private release?

Seems that by doing this they allowed it to become a 0day.

Customers get a week to upgrade under strict embargo

Seems that they can enforce an embargo with their private customers so that it won't become a 0day.

It became a 0day because the security researcher inadvertently kicked off public discussion.

I should clarify that “inadvertently” is the key word here. The 0day happened because of a number of factors detailed in the post, and it isn’t the fault of any one person.

Agreed. We will certainly improve processes on our end as a direct result of this, as well.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.