• LeafletOP
    link
    fedilink
    English
    50
    edit-2
    2 months ago

    You don’t need to do anything, these issues have already been fixed.

    • @blackbrook@mander.xyz
      link
      fedilink
      3
      edit-2
      2 months ago

      Do you mean the specific exploit performed by the author has been fixed? Or the general vulnerability that this exploit was intended to demonstrate has been fixed? The article ends with a What’s Next section discussing the difficulty of the latter, saying

      we don’t think there’s a silver bullet to address the risks caused by the compromise of such central pieces of infrastructure

      and going into detail about the challenges for openSUSE OBS. Are you claiming those challenges have all been solved and exploits like this are no longer possible?

      • LeafletOP
        link
        fedilink
        English
        62 months ago

        The authors found and reported vulnerabilities in Pagure and Open Build Service. These vulnerabilities have since been fixed.