Skip to content

Latest commit

 

History

History
34 lines (30 loc) · 1.58 KB

SECURITY.md

File metadata and controls

34 lines (30 loc) · 1.58 KB

Security Policy

This reporting template is heavily based on HackerOne and inspired by the CVSS calculator, paraphrased from their documentation. The entire repo is included in the scope. You may also use the CVSS Calculator directly and send a screenshot of it; the link is included below.

Reporting a Vulnerability

  1. Which branch or asset is affected?
  2. What is the potential issue? Describe the vulnerability and include known CVEs.
  3. Is user input required? Yes | No
  4. Level of privilege? No login | Basic User | Administrator
  5. CIA Impact? Confidentiality, Integrity, Availability
  6. How can it be reproduced?
  7. Proof of Concept Video, images, written, etc. included

HackerOne. Submitting Reports. HackerOne Platform Documentation. Retrieved November 9, 2022, from https://docs.hackerone.com/hackers/submitting-reports.html

NIST. Common Vulnerability Scoring System Calculator. National Vulnerability Database. Retrieved November 9, 2022, from https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator