|
|
|
|
|
by blincoln
30 days ago
|
|
> When I report serious ones, mostly the devs will respond with something like, yeah, thats how we designed it in a dangerous way, so that the layer above or below can solve the issues, and other footgun stuff. This is one of the reasons that responsible disclosure exists. Their tune will likely change after sufficient bad publicity. If the Apache Solr devs can be convinced to add authentication to their product instead of hand-waving about reverse proxies or other add-ons, anyone can. |
|