Skip to content

Fix vulnerability #2718

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
wants to merge 1 commit into from
Closed

Fix vulnerability #2718

wants to merge 1 commit into from

Conversation

h2oa
Copy link

@h2oa h2oa commented May 9, 2024

Hi featuretools security team,

I submitted a report of vulnerability on huntr.com. I see your product run a bug bounty program on this platform. You can connect to the huntr admin to see details of the report at https://huntr.com/bounties/684bc4d0-3c04-46d6-9076-04bb63f383d0. This pull request is a patch for this vulnerability. Because this is a dangerous vulnerability, please consider it as quickly as possible!

Best regards,
@h2oa

@CLAassistant
Copy link

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

@thehomebrewnerd
Copy link
Contributor

Fixed in #2723

@h2oa
Copy link
Author

h2oa commented May 10, 2024

Hi @thehomebrewnerd ,

Can you notify to the admin of huntr.com to consider and change my report on huntr.com to valid, this will help me receive a reward commensurate with my efforts to find vulnerabilities. Thanks!

Best regards,
@h2oa

@thehomebrewnerd
Copy link
Contributor

@h2oa Thank you for identifying this issue and providing a solution. However, I do not have any involvement with huntr.com, nor does anyone at Alteryx as far as I am aware.

@h2oa
Copy link
Author

h2oa commented May 11, 2024

Hi @thehomebrewnerd,

I also don't know how huntr.com works, I know that this open source product is running a bug bounty program on it. Can you contact them by sending a mail to https://huntr.com/contact-us? Or you can join their discord at https://discord.com/invite/WrkrrXrF4U.

Best regards,
@h2oa

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants