"Open-Source Vulnerability Disclosure: Exploitable Weak Spots"
"Open-Source Vulnerability Disclosure: Exploitable Weak Spots"
According to Aqua Security researchers, attackers could exploit flaws in the vulnerability disclosure process of open-source projects to gather the information they need to launch attacks before patches are made available. The maintainer is aware of "half-day" vulnerabilities, and information about them is publicly available on GitHub or the National Vulnerability Database, but there is still no official fix.