| ▲ | joshka 10 hours ago | |
There's no reason to think that a tool that can find an 0-day in a repo cache can't work out how to make that host send a post request rather than a get request once it has its keys and is able to get it to make arbitrary web calls. | ||
| ▲ | simonw 10 hours ago | parent [-] | |
If the vulnerability is purely an open redirect that doesn't work for me. Clearly there was a hole in the software but I don't think open redirect is the likely initial problem. Hopefully we will find out for sure in a few days. | ||