• chameleon
      link
      fedilink
      51 year ago

      Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental

      Do note that despite not being enabled by default, it is enabled in the official binary packages.

      There’s a funny amount of layers to this thing but as far as I’m concerned, if it’s a feature you ship in the default binary packages on your site, that is definitively enough for a CVE even if it’s disabled by default.

    • @lorty@lemmygrad.ml
      link
      fedilink
      41 year ago
      • Doesn’t expose information
      • the service/thread just restarts
      • Is an experimental feature
      • that’s not enabled by default

      Yeah I can definitely see why the devs decided to just fix it on the next patch. Reporting a CVE for this feels very unnecessary.