Access permissions in rpcd and uhttpd
Jo-Philipp Wich
jo at mein.io
Sun Jul 19 23:23:06 PDT 2026
Hi Hauke,
> I send this mail to the public mailing list because I want such a
> discussion. I do not think these are big problems we have to manage in
> private and then release in a coordinated way.
> [...]
I agree, such "low impact" report can be published right away and fixed
on the next occasion, basically handle them like an ordinary issue report.
The disclosure / CVE request flow etc. should be reserved for high
impact issues like unauthenticated code injection or similar.
Regards,
Jo
More information about the openwrt-devel
mailing list