?
avatar kevinoclam
kevinoclam
11 Apr 2017

I have found a vuln of joomla and report the detail to security@joomla.org.
According to https://developer.joomla.org/security.html , I should get acknowledged response already ,but actually , I didn't get anyone.
My email address is chenruiqi@b.360.cn
In the email, I test joomla 3.6.5 , just now , I test Joomla! 3.7.0 Release Candidate 1 and it works.
I just want to know whether you have get the mail.

Steps to reproduce the issue

Expected result

Actual result

System information (as much as possible)

Additional comments

avatar kevinoclam kevinoclam - open - 11 Apr 2017
avatar joomla-cms-bot joomla-cms-bot - change - 11 Apr 2017
Labels Added: ?
avatar joomla-cms-bot joomla-cms-bot - labeled - 11 Apr 2017
avatar kevinoclam kevinoclam - edited - 11 Apr 2017
avatar jeckodevelopment
jeckodevelopment - comment - 11 Apr 2017

@SniperSister can you check please?

avatar joomla-cms-bot joomla-cms-bot - change - 11 Apr 2017
Title
A security vuln of joomla report to security@joomla.org but get no response after almost 5 days
A security vuln of joomla report to security@joomla.org but get no response after almost 4days
avatar joomla-cms-bot joomla-cms-bot - edited - 11 Apr 2017
avatar franz-wohlkoenig franz-wohlkoenig - change - 11 Apr 2017
Priority Medium Urgent
avatar franz-wohlkoenig franz-wohlkoenig - change - 11 Apr 2017
Category Administration
avatar gwsdesk
gwsdesk - comment - 11 Apr 2017

Just in general to get the fastest reply I guess the best way is to use the VEL Reporting tool https://vel.joomla.org/submit-vel


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/15218.

avatar demis-palma
demis-palma - comment - 11 Apr 2017

VEL is for the extensions, while @kevinoclam reported a Joomla issue. Please wait until we got a reply from David.

avatar gwsdesk
gwsdesk - comment - 11 Apr 2017

@demis-palma that is incorrect and I quote "We accept reports of security vulnerabilities for Joomla and Joomla extensions"

avatar zero-24
zero-24 - comment - 11 Apr 2017

@kevinoclam i have just checked the internal mailing list and i can not find any messages. Did you get any kind of auto responder to your message?

To be sure please use this form to get in contact with the JSST: https://developer.joomla.org/security/contact-the-team.html

avatar kevinoclam
kevinoclam - comment - 11 Apr 2017

Thanks a lot.
@zero-24 I didn't use the form because I don't know how to attach a picture, and I didn't get any auto response. I send the email directly with outlook. Now I have used the form to send the report.
@gwsdesk Thanks a lot too, I also send a report via the VEL Reporting tool .

avatar zero-24
zero-24 - comment - 11 Apr 2017

@kevinoclam hmm I still can't see it in the list. Please send it to my community account so I can share it with the other members of the JSST. Thanks.

avatar mbabker
mbabker - comment - 11 Apr 2017

It's in the security@ email. Unfortunately Google's mail filters flagged it as spam so our ticketing system didn't receive it.

avatar jeckodevelopment
jeckodevelopment - comment - 11 Apr 2017

So since it has been received properly, i guess we can close this issue.
Thanks Tobias and Michael ;)

avatar jeckodevelopment jeckodevelopment - change - 11 Apr 2017
Title
A security vuln of joomla report to security@joomla.org but get no response after almost 4days
A security vuln of joomla report to security@joomla.org but get no response after almost 5 days
Status New Closed
Closed_Date 0000-00-00 00:00:00 2017-04-11 12:08:18
Closed_By jeckodevelopment
avatar jeckodevelopment jeckodevelopment - close - 11 Apr 2017

Add a Comment

Login with GitHub to post a comment