Skip to content

Commit

Permalink
Update SECURITY.md
Browse files Browse the repository at this point in the history
  • Loading branch information
ar2rsawseen authored Jan 23, 2023
1 parent 007abe3 commit 49ef1cf
Showing 1 changed file with 13 additions and 1 deletion.
14 changes: 13 additions & 1 deletion SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,4 +4,16 @@ Security is very important to us. If you discover any issue regarding security,

All software related security bugs with severity of medium and higher will be awarded accordingly with a bug bounty reward.

Due to on premise nature of our software, all server configuration related issues will be reported to related departments/parties/companies, but we cannot guarantee any bounty rewards for them.
# Vulnerability levels
**Critical Severity:** software can be exploited at any time without any additional information

**High Severity:** some additional information, access or action required (from the user, like clicking on injected link) for software to be exploited

**Medium Severity:** the impact is limited (for example, can only access limited information) or requires special conditions to achieve it (when server is configured in specific way)

**Low** - no bounty rewards, does not directly lead to vulnerability, but provides a possibility (like exposing software version, which can be mapped to specific vulnerabilities), old dependencies, server misconfiguration

**Exclusion**

Server specific configurations and deployment specific configurations due to on premise nature of our software.
All server configuration related issues will be reported to related departments/parties/companies, but we cannot guarantee any bounty rewards for them.

0 comments on commit 49ef1cf

Please sign in to comment.