Vulnerability Report
1. Definition
A vulnerability is a defect or weakness in system design, deployment, operation, and management that can be exploited to violate system security policies.
2. Vulnerability Management Philosophy
This community attaches great importance to the security of community versions. Although the industry consensus is that security vulnerabilities are inevitable, the community will still adhere to the following principles to actively reduce the potential risks of security vulnerabilities.
Proactive Management: Take measures to reduce security vulnerabilities in products and services;
Open Collaboration: Work closely with upstream and downstream communities to provide timely risk mitigation solutions to customers for security vulnerabilities found in products and services.
3. Security Vulnerability Handling Process
Security Vulnerability Awareness: For upstream open-source software and original open-source projects within the community, multiple security vulnerability awareness and reception channels have been established, including community contributors actively submitting security vulnerabilities, obtaining community-related security vulnerabilities through email feedback, etc.
| Vulnerability Type | Perception Channel | Reporting Method |
|---|---|---|
| Original Open Source Software/Upstream Open Source Software | Contributors | Submit security vulnerability issues on Gitee |
| Community Security Vulnerabilities | All Community Users | Security Vulnerability Management Email [EMAIL] |
When reporting a security vulnerability, please provide as much of the information requested below as possible to help us better understand the nature and scope of the issue.
The type of issue.
The full path of the source files related to the manifestation of the issue.
The location of the affected source code.
Any special configuration required to reproduce the issue.
Step-by-step instructions to reproduce the issue.
Proof-of-concept or exploit code.
The impact of the issue, including how an attacker might exploit it.
This information will help us process your report more quickly.
Security Vulnerability Fix: For confirmed valid security vulnerabilities, the Technical Oversight Committee will organize to complete the fix as soon as possible. For more serious security vulnerabilities, the community will increase the processing priority.
Security Vulnerability Tracking: Conduct security testing and review work to prevent security incidents from recurring after restoration due to incomplete fixes.
Security Vulnerability Disclosure: Follow the principle of responsible disclosure, summarize the recent security vulnerability handling process, improve the points with defects in the work, improve the emergency work system, and output a complete security incident management report.