Skip to content

Security: contentful/apps

Security

SECURITY.md

Security Policy

Security at Contentful

Security being just important to us is a huge understatement. Security is a top priority at Contentful and we live it in our day-to-day activities.

If you believe you have found a security vulnerability in any Contentful-owned repository, please report it to us as described below.

Supported Versions

Refer to individual repositories for supported versions.

Reporting a Vulnerability

Contentful engages with the community via our Responsible Disclosure Program, also known as our Bug Bounty Program. Our community plays an important role in helping us stay bug-free and secure.

Found a vulnerability? Would you like to report a bug or something interesting that you found? The best way to reach out to us is via the submission form at the end of the page.

Please include the requested information listed below (as much as you can provide) to help us better understand the nature and scope of the possible issue:

  • Type of issue (e.g. buffer overflow, SQL injection, cross-site scripting, etc.)
  • Full paths of source file(s) related to the manifestation of the issue
  • The location of the affected source code (tag/branch/commit or direct URL)
  • Any special configuration required to reproduce the issue
  • Step-by-step instructions to reproduce the issue
  • Proof-of-concept or exploit code (if possible)
  • Impact of the issue, including how an attacker might exploit the issue

This information will help us triage your report more quickly.

Report security vulnerabilities in third-party modules to the person or team maintaining the module.

There aren’t any published security advisories