<Foxboron>
>Impact: SSL cert not verified by default
<Foxboron>
Probably the highlight. In the middle of the list as well :D
<hexa->
yeah
<andi->
python and not validating certs properly. Who would have guessed :D (You have to do all kinds of validation as the library doesn't do anything besides "is signed and not expired")
<ajs124>
At least they're getting themselves a CVE, unlike some projects.
<Foxboron>
They are used in enterprise environments so they would loose quite a bit of money if they didn't
<ajs124>
Seems like inverse inc (the people developing the SOGo groupware) never got that memo
cole-h has joined #nixos-security
justanotheruser has joined #nixos-security
justan0theruser has quit [Ping timeout: 272 seconds]
rajivr has quit [Quit: Connection closed for inactivity]
justan0theruser has joined #nixos-security
justanotheruser has quit [Ping timeout: 260 seconds]
justanotheruser has joined #nixos-security
justan0theruser has quit [Ping timeout: 272 seconds]