Hacker News new | ask | show | jobs
by SideburnsOfDoom 3024 days ago
> What an awful disclosure. Fails to mention what "validating a request correctly" means.

Click one link, the first one in the main page text, scroll down, and you're here (1)

> Q: Are there any more details on what "fails to validate web requests correctly" means and/or a PoC for this?

> A: No. We don’t publish more details or PoCs.

This seems entirely deliberate and unsurprising on day 1 when few have applied the patch yet, and is therefore not "awful".

1) https://github.com/aspnet/Home/issues/2954#issuecomment-3728...

1 comments

Actually and if you're against full disclosure it's the exact reverse of "awful".
I'm in favour of full disclosure ... eventually. Today does not seem like the right time for that yet.