Skip to content

Security: koo-projects/pufferpanel

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
3.x.y
2.x.y
1.x.y
0.x.y

Reporting a Vulnerability

Reporting sensitive information may be done by submitting a request on https://github.com/pufferpanel/pufferpanel/security/advisories

Expectations

Reports which do not contain a valid subject or desciption will be ignored.

Likewise, AI written or produced reports will be closed. You can use AI to assist, but write the report yourself. More often than not, the report the AI generates is wrong, and it wastes our time.

Where possible, include a PoC showing how to trigger the vulnerability.

Permissions that require creating servers or editing definitions or templates are considered "administrative" permissions, and as such, are not considered for cases such as installing arbitrary binaries.

Process

While we know there are "standards" in how reporting and fixing security advisories are done, we do not fully follow all those standards. Due to our lack of understanding of the entire process and documentation being extremely verbose, we follow a variant of the process.

  1. We will review a draft advisory under the lense of a typical administrator and user.
  2. If the report is considered valid, we will accept the draft.
  3. During this process, we will work to create a fix and unit tests to validate the issue is both reproduceable and resolved.
  4. Due to this being an open source project, the fix will be committed to the repo directly. The unit tests may be pushed a few weeks after as they may contain clear steps to execute the vulnerability.
  5. We will then close the advisory without creating a CVE. Due to our release cycle, we are not certain the way Github does this process flows with our own process. For now, we only use their system to report them to us.

There aren't any published security advisories