Comment on An update on 0day CVE-2021-43798: Grafana directory traversalComments−graffgejrkk4y2021-12-03: Release plan set: 2021-12-07 for private customer release, 2021-12-14 for public releaseDoes someone know why they were playing on sitting on the public release for a week after private release?Seems that by doing this they allowed it to become a 0day.−alphahsl4yCustomers get a week to upgrade under strict embargoSeems that they can enforce an embargo with their private customers so that it won't become a 0day.It became a 0day because the security researcher inadvertently kicked off public discussion.−alphahsl4yI should clarify that “inadvertently” is the key word here. The 0day happened because of a number of factors detailed in the post, and it isn’t the fault of any one person.−RichiH4yAgreed. We will certainly improve processes on our end as a direct result of this, as well.
Comments
Does someone know why they were playing on sitting on the public release for a week after private release?
Seems that by doing this they allowed it to become a 0day.
Seems that they can enforce an embargo with their private customers so that it won't become a 0day.
It became a 0day because the security researcher inadvertently kicked off public discussion.
I should clarify that “inadvertently” is the key word here. The 0day happened because of a number of factors detailed in the post, and it isn’t the fault of any one person.
Agreed. We will certainly improve processes on our end as a direct result of this, as well.