你好 @dhigby ,这不是我的本意。我只是在询问是否有推荐的报告已发现安全漏洞的方式。
有时,安全漏洞的认定存在争议,并非所有报告都是有效的。报告需要私下进行,以防止向潜在攻击者泄露漏洞信息。如果漏洞未被修复,负责任的披露就会变成公开披露,以便用户在可能的情况下采取措施保护自己。本线程并非对漏洞的公开披露。
Hi @dhigby , that was not my intention. I was merely asking about the preferred way of reporting a discovered security vulnerability, if there was one.
Sometimes, security vulnerabilities are debatable, and not all reports are valid. Reports need to be made privately, to prevent disclosing the vulnerability to potential attackers. If the vulnerability is not fixed, responsible disclosure becomes public disclosure, so that users can take measures to protect themselves, if possible. This thread is not a public disclosure of a vulnerability.
机器翻译自 English