GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    pistolero :thispersondoesnotexist: (p@freespeechextremist.com)'s status on Sunday, 01-Oct-2023 09:04:54 JSTpistolero :thispersondoesnotexist:pistolero :thispersondoesnotexist:
    in reply to
    • shrimps!
    • sysrq
    • :netbsd: Nishi
    @animeirl @sysrq @nishi

    > a constant deluge of CVEs

    The problem is that you don't understand Hoare's Dictum and you make terrible, massive, shit codebases.

    $ jq -r '.problemtype.problemtype_data |map(.description | map(.value) | join(" ")) | join("\n")' 2023/*/* | sort | uniq -c | sort -n

    111 Out-of-bounds Read (CWE-125)
    120 CWE-20: Improper Input Validation
    134 CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
    153 CWE-862 Missing Authorization
    153 Information disclosure
    157 Information Disclosure
    188 CWE-20 Improper Input Validation
    193 Elevation of privilege
    194 CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    274 Remote Code Execution
    292 CWE-79 Cross Site Scripting
    313 CWE-79 Cross-Site Scripting (XSS)
    353 Elevation of Privilege
    366 CWE-352 Cross-Site Request Forgery (CSRF)
    541 CWE-89 SQL Injection
    1154 CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


    Goddamn, looks like it's almost all webshit.
    In conversationSunday, 01-Oct-2023 09:04:54 JST from freespeechextremist.compermalink
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.