Skip to content

Comment on Roundcube Webmail: SVG feImage bypasses image blocking to track email opens

Comments

You disclosed this the day roundcube was patched. Isn’t it usual to give us time to deploy updates before disclosing details?!

The patch disclosed details pretty clearly already.

https://github.com/roundcube/roundcubemail/commit/26d7677

You give the developer time to develop a patch. Once the patch is out, attackers can already deduce the vulnerability by looking at what changed and at that point you either want to immediately install the patch or you want to know what the vulnerability actually is so you can do something to mitigate it if there is some reason you can't immediately install the patch.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.