All incidents

Security audit results

Summary

Vulnerability #1: Remote code execution

Issue description

Current status

Vulnerability #2: Retrieval of HTTP-only cookies

Issue description

Current status

Vulnerability #3: User enumeration

Issue description

Current status

Vulnerability #4: e-mail HTML injection

Issue description

Current status

Event timeline

  • 2019-01-22 17:30 CET: Receive an email from security researcher
  • 2019-01-22 17:55 CET: Acknowledge reception and reported issues
  • 2019-01-31 08:55 CET: Start working on a fix
  • 2019-02-04 20:55 CET: Fix ready, communicate back with researcher
  • 2019-02-12 12:00 CET: Fix rolled out as part of release v2.7

Current status:

Last updated: 2019-02-12 12:00:00 CET
Flag of European UnionMade in Europe. Privacy by default.