> [...]
> 2023-05-04: We privately shared the findings with security@...illa.org, offering coordinated disclosure according to the openSUSE disclosure policy.
> Until 2023-06-12: There has been a lack of communication by upstream. Relevant questions about the disclosure process remained unanswered, there was no formal reply to our report and no wishes have been expressed about how to continue the coordinated disclosure, or what the next steps would be.
> 2023-06-12: We learned that the embargo over this issue was violated by upstream via a GitHub PR [3] and, inspired by that, our community packager followed suit via another GitHub PR [5].
What a complete clusterfuck. It's unbelievable that in 2023, a company of Mozilla's stature appears to have no proper processes in place for handling serious security vulnerabilities even when they are being reported to them (for free!) by cooperative third parties.
This taints the image of the entire product in my view.