Section 05
Vulnerabilities are handled in public or not at all
The strike team, CVEs, and 2015.

A documented process is the difference between a project that can be handed a CVE and one that cannot.
3 pieces in this section
- A standing team, and a published processThe Joomla Security Strike Team handles reports on a documented process, which is the difference between a project that can be trusted with a CVE and one that cannot.
- A 2015 SQL injection reached a very large number of sitesThe December 2015 vulnerability was exploited widely because the installed base included many sites nobody was updating.
- The real vulnerability is the abandoned installA CMS that is easy to install produces installations with no owner, and those are what get compromised.
Other sections