Re: Best avenue for reporting security issues

2013-12-19 Thread Paul Querna
http://www.apache.org/security/ email secur...@apache.org since there isn't a Cassandra specific security list. This will also help with getting things like CVEs assigned and making sure balls are not dropped. On Tue, Dec 17, 2013 at 3:30 PM, Ben Bromhead wrote: > Hi guys > > We’ve come across

Re: Best avenue for reporting security issues

2013-12-17 Thread Ben Bromhead
No worries, message sent Ben Bromhead Instaclustr | www.instaclustr.com | @instaclustr | +61 415 936 359 On 18 Dec 2013, at 10:35 am, Aleksey Yeschenko wrote: > Hi Ben, > > Send it to me, I'll handle it. > > Thanks > > > On Wed, Dec 18, 2013 at 2:30 AM, Ben Bromhead wrote: > >> Hi guys >>

Re: Best avenue for reporting security issues

2013-12-17 Thread Aleksey Yeschenko
Hi Ben, Send it to me, I'll handle it. Thanks On Wed, Dec 18, 2013 at 2:30 AM, Ben Bromhead wrote: > Hi guys > > We’ve come across a bug with potential security implications and in the > spirit of responsible disclosure whats the best path for reporting it / > submitting patches without makin

Best avenue for reporting security issues

2013-12-17 Thread Ben Bromhead
Hi guys We’ve come across a bug with potential security implications and in the spirit of responsible disclosure whats the best path for reporting it / submitting patches without making the issue public until a fixed version of Cassandra is released? As a follow up I would propose that the Cas