Skip to content

Commit a8e6f36

Browse files
rrobergerlxdev
authored andcommitted
Update SECURITY.md
Update CVE website Security Policy
1 parent f75806d commit a8e6f36

1 file changed

Lines changed: 11 additions & 17 deletions

File tree

SECURITY.md

Lines changed: 11 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -1,22 +1,16 @@
11
# Security Policy
22

33
## Reporting a Vulnerability
4-
Please use the <a href="https://cveform.mitre.org/" target="_blank">CVE Program web forms</a> to report security vulnerabilities for the
5-
<a href="https://www.cve.org" target="_blank">CVE website</a>. Please include vulnerability details, steps to reproduce (e.g., proof-of-concept code,
6-
screenshots) and an assessment of the impact in your report. We appreciate concise and high-quality reports.
7-
8-
## Web Form Submissions
9-
10-
* In the “Select a request type” drop down menu, please select “Other”
11-
* Enter your email address in the space provided
12-
* You may enter a PGP key if you prefer to encrypt your correspondence
13-
* In the “Type of comment” drop down menu, please select “Issue”
14-
* In the textbox labeled “Please provide your question, issue, comment, etc.” please start the message with the following information:
15-
- First Line: “CVE Website Security Anomaly Report”
16-
- Second Line: “Distribution: CVE Website Development Team”
17-
- Third Line: "Description: [Free Text description of the anomaly]
18-
* Enter the Security code
19-
* Click “Submit Request”
4+
Please use the <a href="https://cveform.mitre.org/" target="_blank">CVE Program Web Forms</a> (choose “General Support”) to report security vulnerabilities for the
5+
<a href="https://www.cve.org" target="_blank">CVE website</a>.
6+
7+
Please include:
8+
9+
* Vulnerability details
10+
* Steps to reproduce (e.g., proof-of-concept code, screenshots)
11+
* An assessment of the impact
12+
13+
We appreciate concise and high-quality reports.
2014

2115
## Scope
2216

@@ -28,4 +22,4 @@ We will release fixes for verified security vulnerabilities. We expect to publis
2822
<a href="https://github.com/CVEProject/cve-website/security/advisories" target="_blank">security advisories</a>.
2923

3024
## Coordination
31-
We appreciate the opportunity to investigate and develop fixes before public disclosure, following coordinated vulnerability disclosure practices.
25+
We appreciate the opportunity to investigate and develop fixes before public disclosure, following coordinated vulnerability disclosure practices.

0 commit comments

Comments
 (0)