mirror of
https://bitbucket.org/jsuto/piler.git
synced 2024-12-25 07:40:12 +01:00
20 lines
632 B
Markdown
20 lines
632 B
Markdown
|
Disclosure policy
|
||
|
|
||
|
If you find a security issue, please contact the project owner at sj@acts.hu
|
||
|
with the details (ie. piler version, details of the setup, how to exploit the
|
||
|
vulnerability, etc).
|
||
|
|
||
|
Please provide 30 days for verifying the vulnerability, fixing the issue, and
|
||
|
notifying the piler users.
|
||
|
|
||
|
Security update policy
|
||
|
|
||
|
If a security vulnerability has found, the details, possible mitigations,
|
||
|
workarounds, etc. will be shared on the piler mailing list (piler-user@list.acts.hu)
|
||
|
and on the wiki: http://www.mailpiler.org/
|
||
|
|
||
|
Security configurations
|
||
|
|
||
|
- Use https for the GUI
|
||
|
- Reset the default passwords for admin and auditor
|