{
"id":"b8b6c7db45085d0c18d99f83f9a6962e9979b816df2045b1a155367926b4b36a",
"pubkey":"f635dd675b5638d6cd137a24b560ed378e1fac164143be4011ab93181911fe04",
"created_at":1723837090,
"kind":1,
"tags": [
[
"t",
"gemini"
],
[
"t",
"vuln"
],
[
"proxy",
"https://fe.disroot.org/objects/85956965-ac55-4550-af3f-24da666211fb",
"activitypub"
]
],
"content":"I found vulnerability in buran(Android gemini client)\n\nBuran continues to open the https link after it is closed.\nThis causes the subsequent URL to be leak.\n\nBelow I have provided nginx access log and my video of exploitation of vulnerability\n\n#vuln #gemini\n\nhttps://fe.upload.disroot.org/media/1be223bbbbd16cba1f29351b6864a2e8e0f1eac7fc9f64d1f132f31c92fd6173.png\n\nhttps://fe.upload.disroot.org/media/f7016a3db4fdc6ebbf5e31c33fee2824128b38d882e364f84070a1ba4a8cc2be.mp4",
"sig":"bf6c8b29a1f8c0a28b2dfbce1bd761346267cf4ba500eb232db2d43b627d3122bc6d1a9df9bec0a919abb32cfa0ceb2ea4e807d30b40514084996b575d34a410"
}