For all these issues, the description is only “Details will be provided later.”
All 4 issues were resolved over a month ago. Please can they be updated with details ASAP. Otherwise, how can SQ admins decide whether or not they are impacted and need to upgrade sooner rather than later?
Thanks for the question. It’s very valid and it prompted me to ping the Product Manager to make a public statement on his policy around this. And that… prompted him to re-examine the policy.
I say “long run” because to really make VEX work for communicating to thousands of customers, there need to be a transport mechanism. But that is coming…
Sorry for the delay. We added to these tickets an estimation of the severity (revised CVSS) to help you decide if you have to upgrade immediately or not.
We’ll provide more details about the fixed vulnerabilities 90 days after the release so that users have time to upgrade.
You can expect a more formal public statement about this policy soon.