Hacker News new | ask | show | jobs
by nucleardog 1063 days ago
Wow that CVE is absurd.

“If you pass a password via the command line, other processes on the system could see it via ps.”

Yeah, no shit. If that qualifies as a “high severity” CVE then, uh, you can call me a security researcher because I can think of at least a half a dozen applications that allow the exact same thing with the exact same disclaimer (“don’t do this”).

1 comments

On good authority, CVE Severity is nonsense

https://daniel.haxx.se/blog/2023/03/06/nvd-makes-up-vulnerab...