On Wed, Aug 19, 2026 at 07:31:12PM +0200, Michael Biebl wrote:
> The CVSS metric for this bug says 7.5/10, which I suppose is mostly due to
> the network attack vector.
> 
> Given the module is not enabled by default and I would suspect it's not that
> widely used, I would say a security upload is not necessary and I would just
> make a stable upload for rsyslog.

Sounds good! We've marked it as no-dsa.

The CVSS score is a good example why these are so useless in
practice and why Debian doesn't use them: While this is of course a network
attack vector, it's not like an rsyslog would be exposed to the public 
internet...

Cheers,
        Moritz

Reply via email to