Openai脆弱性:48天,没有回应
OpenAI – vulnerability responsible disclosure

原始链接: https://requilence.any.org/open-ai-vulnerability-responsible-disclosure

我选择通过官方披露电子邮件报告此漏洞,而不是通过漏洞赏金平台报告其披露协议中的条款。当您通过他们的门户提交时,您需要同意不要分享有关您发现的问题的任何信息 - 本质上是封闭式的披露,即使在修复后,也可以阻止研究人员公开讨论他们的发现。

相关文章

原文
I chose to report this vulnerability via official disclosure email rather than through the bug bounty platform because of concerning terms in their disclosure agreement. When you submit through their portal, you're required to agree not to share any information about the issue you found - essentially a blanket non-disclosure that prevents researchers from discussing their findings publicly, even after remediation.
联系我们 contact @ memedata.com