Val Town Blog 10月02日
Val Town安全漏洞紧急修复
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

Val Town宣布发现并修复一个关键安全漏洞,已更新数据库密钥,并暂停服务进行修复。公司正在积极寻找替代方案,并鼓励用户谨慎处理敏感信息。

Security Disclosure 1

on

Today we were alerted to a critical security vulnerability in Val Town. We immediately closed the vulnerability, investigated its scope, rotated our keys, suffered some downtime, and restored the service to full functionality.

We are very confident that this vulnerability was not exploited while it was open. Out of an abundance of caution, we rotated our database keys, which caused some downtime.

The bug was an insecurity in our sandboxing, which is currently based on vm2. We’re actively working on replacing vm2 with Deno and hope to be running on Deno by next week. We’ll keep you all updated on that progress. Big thanks to the user who reported the bug - Philip Papurt - @ginkoid!

In the meanwhile, we’d like to discourage you from putting any particularly sensitive information into Val Town.

We are a new company and want to earn your trust over time. We are not yet confident in our security position and we want to be totally clear about that. Val Town should currently be used mostly for accessing unauthenticated API or APIs where it wouldn’t be a big deal if your auth tokens were exposed.

We apologize for this incident and hope to have a better sandboxing story for you all very soon. Thank you for your patience!

If you discover any other security vulnerabilities, please contact steve@val.town. Thank you!

Timeline

12<37>37> PM ET - notified of vulnerability

1<18>18> PM ET - closed the vulnerability

1<35>35> PM ET- rotated our keys, downtime started

1<37>37> PM ET - backend back up

1<42>42> PM ET - frontend back up

Edit this page

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

安全漏洞 Val Town 数据库密钥 修复
相关文章