1Password CLI Vulnerability
codeberg.org
1Password CLI Vulnerability
1–10 of 67 posts
Re: 1Password CLI Vulnerability
#2[deleted]
Re: 1Password CLI Vulnerability
#3Great work and thank you for sharing!
I will definitely disable the CLI integration.
Hoping 1Password fixes the CLI flow soon.
Re: 1Password CLI Vulnerability
#4is this just a "vulnerability" in the same way sudo doesn't ask for password for a short time after first use ?
Re: 1Password CLI Vulnerability
#5[flagged]
Re: 1Password CLI Vulnerability
#6Great work and thank you for sharing! I will definitely disable the CLI integration. Hoping 1Password fixes the CLI flow soon.
[flagged]
Re: 1Password CLI Vulnerability
#7> Responsible disclosure was made via BugCrowd on 2nd October, 2023, and disclosure was authorized in January of 2024
I’m confused why this is just be publicly disclosed. It’s been known for 2 years!
Re: 1Password CLI Vulnerability
#8[flagged]
Reported to 1Password 2023, disclosure authorized by 1Password 2024, repo published yesterday, no?
Re: 1Password CLI Vulnerability
#9> Responsible disclosure was made via BugCrowd on 2nd October, 2023, and disclosure was authorized in January of 2024 I’m confused why this is just be publicly disclosed. It’s been known for 2 years!
> This investigation took a while, and I waited a while before publishing this disclosure (life circumstances and giving 1Password time to fix the issue).
Sounds like the person really came from a supportive place and hoped things would get sorted out. And had life intervene along the way maybe.