Skip to content
This repository has been archived by the owner on Jan 5, 2023. It is now read-only.

Responsible disclosure policy #70

Closed
zidingz opened this issue Oct 11, 2021 · 8 comments
Closed

Responsible disclosure policy #70

zidingz opened this issue Oct 11, 2021 · 8 comments

Comments

@zidingz
Copy link

zidingz commented Oct 11, 2021

Hey there!

I belong to an open source security research community, and a member (@Haxatron) has found an issue, but doesn’t know the best way to disclose it.

If not a hassle, might you kindly add a SECURITY.md file with an email, or another contact method? GitHub recommends this best practice to ensure security issues are responsibly disclosed, and it would serve as a simple instruction for security researchers in the future.

Thank you for your consideration, and I look forward to hearing from you!

(cc @huntr-helper)

@patkon
Copy link
Member

patkon commented Oct 11, 2021

Hey @zidingz,
i will add a security.md the next days. Let me do a little more research, what's the best way to go.

@Haxatron
Copy link
Contributor

Hi @patkon , here are the reports for the repository (in decreasing order of severity)

https://www.huntr.dev/bounties/3c293dca-d6ba-41b7-8954-8749d729a150/
https://www.huntr.dev/bounties/389d9b0f-d2d3-4355-ba11-99cff5ce0c91/
https://www.huntr.dev/bounties/62e2fd02-cdbf-4252-bbc3-f8c8fa8e13c4/
https://www.huntr.dev/bounties/c3ca21ca-6e10-4cba-82b3-d74bc7a7c62b/

When you are free, you can check them (only maintainers of a repository can view the report)

@Haxatron
Copy link
Contributor

Note that these reports were tested on the latest version of flatcore-cms (the develop branch)

@patkon
Copy link
Member

patkon commented Oct 12, 2021

Hey @Haxatron, thank you. I will check this and do my best to fix the Bugs.
And thanks for the clear descriptions of the problems.

@Haxatron
Copy link
Contributor

Hi @patkon , once you are done and have the free time, could you validate the reports and submit the fixes? You will also be rewarded the fix bounty once you do, for helping keep your software safe!

Thank you!

@patkon
Copy link
Member

patkon commented Oct 13, 2021

Hi @patkon , once you are done and have the free time, could you validate the reports and submit the fixes? You will also be rewarded the fix bounty once you do, for helping keep your software safe!

Thank you!

Yes, of course I will.. I've changed a lot and I'm currently testing whether everything still works as before.

@Haxatron
Copy link
Contributor

Haxatron commented Oct 14, 2021

Hi there, thanks for validating and fixing the vulnerabilities!

Have submitted 2 more reports:

https://huntr.dev/bounties/ee5fba4a-dd6a-4bba-b9dd-d73bcca0f38e/
https://huntr.dev/bounties/c32d57a0-2955-4bd5-80a9-9b5648ec2f28/

Please take your time to review them, don't want you to get overwhelmed 😅

@patkon
Copy link
Member

patkon commented Oct 14, 2021

Hi there, thanks for validating and fixing the vulnerabilities!

Have submitted 2 more reports:

https://huntr.dev/bounties/ee5fba4a-dd6a-4bba-b9dd-d73bcca0f38e/ https://huntr.dev/bounties/c32d57a0-2955-4bd5-80a9-9b5648ec2f28/

Please take your time to review them, don't want you to get overwhelmed 😅

Thank you.

@patkon patkon closed this as completed Jan 5, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants