nbhr / php-reverse-proxy

A tiny 'reverse proxy' PHP script with a file-based cache
Apache License 2.0
97 stars 28 forks source link

Security contact #3

Closed mal-tee closed 9 months ago

mal-tee commented 10 months ago

Hello maintainer(s),

I am a security researcher from the Institute of Application Security at TU Braunschweig, Germany. We discovered a (potential) security vulnerability in your project.

We would like to report this vulnerability to you in a responsible and ethical manner. Therefore, we do not want to disclose any details of the vulnerability publicly until you have had a chance to review and fix it.

Could you please let us know your prefered way of receiving security reports?

You can contact us at ias-disclosure@tu-braunschweig.de or by replying to this issue.

Thank you for your attention and cooperation.

nbhr commented 9 months ago

Thank you for letting me know the potential vulnerability. I have enabled "Security Advisories" functionality in this repository. Could you please visit

https://github.com/nbhr/php-reverse-proxy/security/advisories

and draft an advisory as instructed in the GitHub docs?