‹ BackHN Continuity

Thread

A heap overflow and SSO misconfiguration to compromise OpenAI internal repos

491 points · 208 comments · Handy-Man

  1. 6thbit · · focus · HN ↗

      > but the commit was not documented as a security fix and received no CVE.
    
    
    There must be an entire class of open source commits that unknowingly fixed security bugs without being tagged as security fixes that one could look for missed backports. Scary.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.