Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[urgent] CVE-2020-12856 #56

Open
jimmo opened this issue Jun 3, 2020 · 0 comments
Open

[urgent] CVE-2020-12856 #56

jimmo opened this issue Jun 3, 2020 · 0 comments

Comments

@jimmo
Copy link

jimmo commented Jun 3, 2020

This CVE is known to exist in OpenTrace and all forks. It has been assigned a severity of 9.2 Critical. It primarily affects Android but should also be addressed on iPhone.

See https://github.com/alwentiu/COVIDSafe-CVE-2020-12856 for more information.

The details are not currently public and are under embargo until June 19, however we have emailed the full details to [email protected] and [email protected] on May 19 and again on May 27 including details of a suggested fix, but have not heard any reply or acknowledgement.

Please contact us for more information if necessary, but additionally please provide an advisory so that other projects forking OpenTrace do can also be aware of how to address this.

cc @alwentiu

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant