top | item 37974474

(no title)

lsowen | 2 years ago

It took THREE YEARS (August 2020 - August 2023) to fix the vulnerability? I'm not sure the size of the Harvest team, but that still seems insane.

discuss

order

politelemon|2 years ago

I'm guessing, as would be typical of many companies, it ended up on a backlog as low priority, survived a few Jira reorganisations and corporate restructuring, before eventually being noticed and fixed.

bonzini|2 years ago

Probably fixed without even noticing when a dependency was updated...

config_yml|2 years ago

They're a small company with an even smaller engineering team, I think 13 devs or something like that. I would imagine either everyone knows about it immediately or they are too overloaded with work that it gets deprioritised into oblivion after a quick first look.

jorge_leria|2 years ago

Harvest Security Team here. I addressed this on another comment, but basically we were never able to reproduce and there was no explicit fix, but it stayed on Triage state when it should've been Closed, due to a human error on my side.