Actions

Security: Difference between revisions

From Mahara Wiki

No edit summary
Line 10: Line 10:


The Mahara Security Bug Bounty Program has ended. Please see the [https://mahara.org/interaction/forum/topic.php?id=4923 announcement] for further information.
The Mahara Security Bug Bounty Program has ended. Please see the [https://mahara.org/interaction/forum/topic.php?id=4923 announcement] for further information.
We still appreciate bug security bug reports and will list their reporters in the [[Contributors#Security_researchers|Security researchers]] section of our contributors page as a thank you.


= How to report a security issue? =
= How to report a security issue? =

Revision as of 20:29, 20 Haziran 2014

Security is very important to Mahara developers. As potential issues are reported to us, we will test, patch and release fixes as quickly as possible.

In the past, we had a security bug bounty program in place that rewarded researchers for finding security issues and disclosing them to us.

Security announcements

You can see the previous security issues on our bug tracker or subscribe to security announcements from this forum via email or RSS.

Mahara Security Bug Bounty Program

The Mahara Security Bug Bounty Program has ended. Please see the announcement for further information.

We still appreciate bug security bug reports and will list their reporters in the Security researchers section of our contributors page as a thank you.

How to report a security issue?

Please email security issues to [email protected] and provide as many details as you can about the environment (Mahara version, database version, plugins used, etc.).

Alternatively, you can report security issues on our bug tracker if you select the "Private security" option under "This bug contains information that is" when reporting your bug (which will hide the bug and mark it as private).

You will receive a response from a developer acknowledging receipt of your email, typically within 1 or 2 business days. If you do not receive a response, please do not assume we're ignoring you. It's quite possible your email didn't make it through a spam filter.

We appreciate your patience. Some bugs take time to correct and the process may involve a review of the codebase for similar problems. Please do not disclose the vulnerability to anyone before the publication of the official Mahara security advisory.

When contacting us about a security vulnerability. Let us know whether you want to be listed as a security researcher at [1], and if so, how you should be presented.

Security in our development process

Mahara developers are committed to achieving the highest standard of security. All commits to the Mahara git repository are reviewed by at least one developer who will enforce the guidelines found in Developer_Area/How_to_Review_Code.

Some of the developers are also members of the security team and follow these guidelines.