WPIntell

Source evidence

Unpatched Security Vulnerability

Jetpack VaultPress · support · 2017-03-03T07:18:00+00:00

mixedsentiment
highseverity
0.88relevance
3replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

6 / 32 rows with source links

18.8% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

26 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
redsand resolved
Recently the following security vulnerability was announced: VaultPress – Backend Server SSL Verification Disabled Apparently the issue was reported last July but is still unpatched. Please address this issue as soon as possible. Thank you. Thanks for the note. I’m checking into the status of this issue. Howdy again! There’s a fix in place and undergoing final Q&A tests. It’ll be released soon once the rounds are complete. Thanks! @kraftbj , Outstanding. Thanks for the fast response and for working on the update.

Comments

3 shown
Brandon Kraft 2017-03-03T16:57:00+00:00

Thanks for the note. I’m checking into the status of this issue.

Brandon Kraft 2017-03-03T21:25:00+00:00

Howdy again! There’s a fix in place and undergoing final Q&A tests. It’ll be released soon once the rounds are complete. Thanks!

redsand 2017-03-04T04:08:00+00:00

@kraftbj , Outstanding. Thanks for the fast response and for working on the update.