A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an organization will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifiable via a simple way, a security.txt notice.
# Security vulnerability reporting for the MISP Project # is handled by CIRCL Computer Incident Response Center Luxembourg Contact: https://www.circl.lu/contact/ Encryption: http://pgp.circl.lu/pks/lookup?op=get&search=0xEAADCFFC22BD4CD5 Policy: https://github.com/MISP/MISP/blob/2.4/CONTRIBUTING.md#reporting-security-vulnerabilities
This policy crawled by Onyphe on the 2020-07-04 is sorted as securitytxt.
FireBounty © 2015-2024