Comment 1 for bug 1673569

Revision history for this message
Jeremy Stanley (fungi) wrote : Re: Failed notification payload is dumped in logs with auth secrets

Since this report concerns a possible security risk, an incomplete security advisory task has been added while the core security reviewers for the affected project or projects confirm the bug and discuss the scope of any vulnerability along with potential solutions.

If it can be confirmed for certain that the commit introducing this behavior is master-branch-only impacting then we can drop the embargo and forgo the advisory (Class Y report).