Please report security vulnerabilities in the OpenCTEM sensor privately by email to security@openctem.io.
Do not open a public GitHub issue, pull request or discussion for a vulnerability.
Include as much of the following as you can:
- the affected component and version (
openctemio-sensor -version, image tag or digest); - a description of the issue and its impact;
- steps to reproduce, a proof of concept, or the configuration needed;
- any known mitigation or workaround;
- how you would like to be credited, if at all.
| Step | Target |
|---|---|
| Acknowledgement of your report | within 3 business days |
| Triage and an initial assessment | within 10 business days |
| Fix released | typically within 90 days, depending on severity and complexity |
We follow coordinated disclosure: we keep you informed while we work on a fix, agree on a disclosure date with you, and credit you in the release notes unless you prefer otherwise. Please give us a reasonable time to release a fix before you disclose the issue publicly.
Security fixes are made in the latest release. Upgrade to the latest release to receive them.
We will not pursue legal action against anyone who, in good faith, researches and reports a vulnerability under this policy: who avoids privacy violations, data destruction and service disruption, tests only against systems they own or are authorized to test, and gives us the chance to fix the issue before disclosing it.
See the OpenCTEM vulnerability disclosure policy: https://docs.openctem.io/security/vulnerability-disclosure/.