GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    Sexy Moon (moon@shitposter.club)'s status on Thursday, 20-Jul-2023 05:41:07 JSTSexy MoonSexy Moon
    in reply to
    • ?
    • alan
    @cereal @lan mixed feelings here. most H2 users aren't vulernable, the issue is that shitty CVE scanners just see H2 in your depdendencies and match it with a CVE and mark it as a critical vulnerability. you're only vulnerable if you use the library in a nonstandard way.

    On the other hand why are they so resistant to removing that command line option, the CVE is absolutely correct

    it would take little effort if corporations wanted to pay just a little money, to make a downstream fork of H2 that does NOTHING but remove that CLI option and they'll avoid the CVE so they should just DO THAT
    In conversationThursday, 20-Jul-2023 05:41:07 JST from shitposter.clubpermalink
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.