Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Missing security policy. Cannot report security bugs and vulnerabilities. #2115

Closed
xenomuta opened this issue Mar 2, 2024 · 5 comments
Closed
Assignees

Comments

@xenomuta
Copy link

xenomuta commented Mar 2, 2024

Hi friends,

I've come across a couple of security bugs in OSSEC HIDS that I want to disclose responsibly, but couldn't find out how exactly as there is no specific bug reporting contact or Security policy here on your Github, so I've tried mailing Scott R. Shinn, Dan Parriot and Dominik Lisiak on the matter earlier last month, but haven't got a response.

Could you guide me through the correct way of disclosing this to the team, without publicly disclosing the details?

@ddpbsd
Copy link
Member

ddpbsd commented Mar 2, 2024

All I see is an email wanting to disclose some issues, but no issues attached. I haven’t really been involved in the project for a few years, so I‘m guessing Scott is the way to go. Maybe reach out to him on slack or discord?
I also believe full disclosure is responsible.

@xenomuta
Copy link
Author

xenomuta commented Mar 2, 2024 via email

@ddpbsd
Copy link
Member

ddpbsd commented Mar 2, 2024

They’re not mine, they’re ossec‘s.
Ossec.slack.com for slack
And i think this is the discord link
https://discord.gg/CJR5A2gD But I could be wrong, I don’t use it much

@bigtrucker89
Copy link
Contributor

Have you tried the contact in the security.txt file?

https://www.ossec.net/.well-known/security.txt

@bigtrucker89
Copy link
Contributor

Added security policy into github to mirror existing https://www.ossec.net/.well-known/security.txt

@bigtrucker89 bigtrucker89 self-assigned this Mar 12, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants