hyperledger / indy-node

The server portion of a distributed ledger purpose-built for decentralized identity.
https://wiki.hyperledger.org/display/indy
Apache License 2.0
685 stars 657 forks source link

Trying to report a critical security issue #1746

Closed shakreiner closed 2 years ago

shakreiner commented 2 years ago

Hey,

I have a critical security issue to report, and I didn't get any response from security@hyperledger.org Who can I send the issue to?

Thanks!

swcurran commented 2 years ago

When did you send it? Please send it again and I will connect as well with those on the list.

shakreiner commented 2 years ago

I sent an email last Monday asking if this was still the right place to send it. So from your answer, I understand this email is still the place to report to, correct?

swcurran commented 2 years ago

The current process to use is here: https://wiki.hyperledger.org/display/SEC/Defect+Response

Ah...the address has changed recently -- from that page There are two ways to report a security bug. The easiest is to email a description of the flaw and any related information (e.g. reproduction steps, version) to security at lists dot hyperledger dot org.

shakreiner commented 2 years ago

I see. Let me review the current process and I'll send a report to the new address shortly. Thanks

swcurran commented 2 years ago

Good stuff -- thanks. Sorry for the confusion.