logoalt Hacker News

joshkayesterday at 8:54 AM1 replyview on HN

There's no reason to think that a tool that can find an 0-day in a repo cache can't work out how to make that host send a post request rather than a get request once it has its keys and is able to get it to make arbitrary web calls.


Replies

simonwyesterday at 9:07 AM

If the vulnerability is purely an open redirect that doesn't work for me.

Clearly there was a hole in the software but I don't think open redirect is the likely initial problem.

Hopefully we will find out for sure in a few days.