• 1 Post
  • 5 Comments
Joined 1 day ago
cake
Cake day: June 26th, 2026

help-circle
  • _Nemo_@lemmy.mlOPtoSelfhosted@lemmy.worldVulnerabilities on Dockerhub
    link
    fedilink
    English
    arrow-up
    2
    ·
    edit-2
    4 hours ago

    Thank you! While that does allay most security concerns, it does beg the question how useful such a vulnerability tracker is if it doesn’t actually show any relevant vulnerabilies and you constantly have to second-guess what it says. Warning signs that aren’t actually warnings because it’s “just a false alarm” quickly teach personell to not take warnings seriously - unti, onel day, it’s not a false alarm…


  • Thanks for your detailed reply!

    To make that happen, the attacker must […] already have access to the server to upload and process the file, which means that security has already failed.

    Do I correctly assume that by axis you mean shell or even root level access? If not, any of my regular users (turned rogue…) could upload a poisoned raw file which nextcloud would process to, for instance, generate a thumbnail.