We warmly welcome reports of potential security vulnerabilities in our codebases.
Only use the security contacts to report undisclosed security vulnerabilities in ASF projects and manage the process of fixing such vulnerabilities. In particular, this means that:
We will ignore mail sent to these addresses that does not meet these requirements.
A security vulnerability is a bug that breaks reasonable expectations of the project in a way that affects confidentiality, integrity, or availability. Some projects have published a ‘Security Model’ to clarify which guarantees can be expected. You can find the security model pages on the projects overview. Note that results from source code security analysis tools are not accepted without additional analysis showing that the problem indeed violates the project's security model, as such tools commonly produce a significant amount of false positives.
Send your report to the project's security address listed on the projects overview. If the affected project is not listed there, or you are unsure which project is affected, send your report to security@apache.org instead.
Every email you send must meet the following requirements:
[SECURITY]. This matches an exclusion rule on our spam filter and ensures that your report is not accidentally discarded.By sending your report you agree that information from it may be made public after triage (for invalid issues) or after the release of the fix, unless you explicitly request otherwise.
An overview of the vulnerability handling process is:
We will credit you in the public advisory. As a rule we will use the credit information from the initial report, we may not honor later requests for credit updates or additions.
Committers should read a more detailed description of the process. Reporters of security vulnerabilities may also find it useful.