• slazer2au@lemmy.world
      link
      fedilink
      English
      arrow-up
      37
      arrow-down
      2
      ·
      4 days ago

      But there is a difference between an unauthenticated bug and a bug requiring an authenticated user getting some deserialised data.

    • klankin@piefed.ca
      link
      fedilink
      English
      arrow-up
      14
      ·
      4 days ago

      And they just changed the CVE rules to include non-exploitable bugs too.

      My theory is its to pump AI ‘discoveries’ numbers