Hacker News new | ask | show | jobs
by frikkie444 854 days ago
F5 is spinning this to be about not disclosing CVE's when the truth is more that the experimental code that was flagged was not considered production ready and whomever is running it should know they are on their own. This CVE is an obvious bug, and

when your KPI is CVE's per month every bug looks like a CVE

F5 wants this feature prioritized over what Maxim planned, and Maxim doesn't have to comply, he is a volunteer.