blob: 5083d8b6b4acd372d706991d7c5aaf20d062d259 [file] [log] [blame]
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="X-UA-Compatible" content="IE=edge,chrome=1">
<meta charset="utf-8">
<title>Report a security issue | Apache Wicket</title>
<meta name="viewport" content="width=device-width, initial-scale=1" />
<link rel="shortcut icon" href="/favicon.ico" type="image/vnd.microsoft.icon" />
<link rel="stylesheet" href="/css/style.css" type="text/css" media="screen" />
<link href="//maxcdn.bootstrapcdn.com/font-awesome/4.7.0/css/font-awesome.min.css" rel="stylesheet" />
<script src="//code.jquery.com/jquery-1.11.3.min.js"></script>
</head>
<body class="">
<div class="header default">
<div class="l-container">
<nav class="mainmenu">
<div class="nav-logo">
<a href="/"><img src="/img/logo-apachewicket.svg" alt="Apache Wicket"></a>
</div>
<div class="nav-container">
<!-- /start/quickstart.html || /help/security -->
<a href="/start/quickstart.html" class=" nav-items">Quick Start</a>
<!-- /start/download.html || /help/security -->
<a href="/start/download.html" class=" nav-items">Download</a>
<!-- /learn || /help/security -->
<a href="/learn" class=" nav-items">Documentation</a>
<!-- /help || /help/security -->
<a href="/help" class=" nav-items">Support</a>
<!-- /contribute || /help/security -->
<a href="/contribute" class=" nav-items">Contribute</a>
<!-- /community || /help/security -->
<a href="/community" class=" nav-items">Community</a>
<!-- /apache || /help/security -->
<a href="/apache" class=" nav-items">Apache</a>
</div>
<div class="nav-container ">
<a href="https://github.com/apache/wicket" target="_blank"><i class="fa fa-github nav-items"></i></a>
<a href="https://twitter.com/apache_wicket" target="_blank"><i class="fa fa-twitter nav-items"></i></a>
<a href="https://builtwithwicket.tumblr.com" target="_blank"><i class="fa fa-tumblr nav-items"></i></a>
</div>
</nav>
</div>
</div>
<main>
<div class="l-container">
<header class="l-full preamble">
<h1>Report a security issue</h1>
<p>The Apache Software Foundation takes a very active stance in eliminating security problems against the Apache Wicket web framework. When you discover a security problem you should report it immediately to the Wicket PMC.
</p>
</header>
<section class="toc left default ">
</section>
<section>
<p>The Apache Software Foundation takes a very active stance in
eliminating security problems against the Apache Wicket web framework.</p>
<p>For reporting and discussing a security issue you should contact the
Wicket PMC privately.</p>
<p><strong>** PLEASE DO NOT CREATE A SECURITY REPORT IN OUR ISSUE TRACKER **</strong></p>
<p>The issue tracker for Wicket is not the appropriate venue for reporting
security issues as the issue tracker is publicly accessible. Instead,
contact the Wicket PMC privately.</p>
<h3 id="contact-the-wicket-pmc-privately">Contact the Wicket PMC privately</h3>
<p>Send your security issue to <strong>private at wicket.apache.org</strong>. This list
is not publicly available so we can discuss and fix the issue in
private without leaking the info to any bad guys.</p>
<p><a class="button" href="mailto:private@wicket.apache.org?subject=Security%20issue" onclick="window.location.href='mailto:private@wicket.apache.org?subject=Security%20issue';return false;">
<i class="fa fa-shield"></i>
REPORT A SECURITY ISSUE
</a></p>
<p>We treat all security issues seriously and will try to fix them as soon
as possible in all affected versions that we still support.</p>
<h3 id="report-normal-bugs-in-jira">Report normal bugs in JIRA</h3>
<p>The Security Team cannot accept regular bug reports or other queries,
we ask that you use our <a href="/help/#reportbug">bug reporting page</a>
for normal, non-security bugs.</p>
</section>
</div>
</main>
<footer>
<div class="l-container">
<div class="left">
<img src="/img/asf_logo_url.svg" style="height:90px; float:left; margin-right:10px;">
<div style="margin-top:12px;">Copyright © 2021 — The Apache Software Foundation. Apache Wicket, Wicket, Apache, the Apache feather logo, and the Apache Wicket project logo are trademarks of The Apache Software Foundation. All other marks mentioned may be trademarks or registered trademarks of their respective owners.</div>
</div>
</div>
</footer>
</body>
</html>