logoalt Hacker News

tagravesyesterday at 9:53 PM8 repliesview on HN

It's really concerning that the biggest, most eye-grabbing part of this posting is the note with the following: "It’s common for critical CVEs to uncover follow‑up vulnerabilities."

Trying to justify the CVE before fully explaining the scope of the CVE, who is affected, or how to mitigate it -- yikes.


Replies

treeskneesyesterday at 10:01 PM

What’s concerning about it? The first thing I thought when I read the headline was “wow, another react CVE?” It’s not a justification, it’s an explanation to the most obvious immediate question.

show 3 replies
rickhanloniiyesterday at 10:17 PM

Thanks for the feedback, I adjusted it here so the first note is related to the impacted versions:

https://github.com/reactjs/react.dev/pull/8195

show 1 reply
0xblinqtoday at 5:03 AM

I think the same. To me it looks like a Vercel marketing employee wrote that.

hitekkeryesterday at 10:38 PM

There are a lot of careers riding on the optics here.

show 1 reply
samdoesnothingyesterday at 10:08 PM

Also kind of funny that they're comparing it to Log2Shell. Maybe not the best sort of company to be keeping...

show 1 reply
zwnowyesterday at 10:01 PM

Welcome to the React, Next, Vercel ecosystem. Our tech may be shite but we look fancy.

show 1 reply
TZubiriyesterday at 11:57 PM

Very standard in security, announcements always always always try to downplay their severity.

show 1 reply