Will you release any information about the vulnerability?
Yes, we’ll be releasing the patch publicly, as well as a CVE and an explanation in two weeks. We’re delaying release to give our install base a bit of extra time before this is widely exploited.
Comments
It is definitely not announced on Full Disclosure nor on oss-security mailing lists.
Doesn't look like there is a CVE either: https://www.cvedetails.com/vulnerability-list/vendor_id-1947...
From their blog.
Oh absolutely, but its trivial to get a CVE from the relevant CNA's. A webform or a phone call.
Its a bit silly.
Don't you have to share more details about the exploit then? That seems to be the thing they're trying to avoid for now.
Negative, you can request a CVE without specific details, CNA's do this all the time until unembargo.