Zend Framework — Reporting Potential Security Issues

If you have encoun­tered a poten­tial secu­rity vul­ner­a­bil­ity in Zend Frame­work, please report it to us at zf-security@zend.com. We will work with you to ver­ify the vul­ner­a­bil­ity and patch it.

When report­ing issues, please pro­vide the fol­low­ing information:

  • Component(s) affected
  • A descrip­tion indi­cat­ing how to repro­duce the issue
  • A sum­mary of the secu­rity vul­ner­a­bil­ity and impact

We request that you con­tact us via the email address above and give the project con­trib­u­tors a chance to resolve the vul­ner­a­bil­ity and issue a new release prior to any pub­lic expo­sure; this helps pro­tect Zend Frame­work users and pro­vides them with a chance to upgrade and/or update in order to pro­tect their applications.

For sen­si­tive email com­mu­ni­ca­tions, please use our PGP key.

Pol­icy

Zend Frame­work takes secu­rity seri­ously. If we ver­ify a reported secu­rity vul­ner­a­bil­ity, our pol­icy is:

  • We will patch the cur­rent release branch, as well as the prior two minor release branches.
  • After patch­ing the release branches, we will imme­di­ately issue new secu­rity fix releases for each patched release branch.
  • A secu­rity advi­sory will be released on the Zend Frame­work site detail­ing the vul­ner­a­bil­ity, as well as rec­om­men­da­tions for end-users to pro­tect them­selves. Secu­rity advi­sories will be listed at http://framework.zend.com/security/advisories, as well as via a feed (which is also present in the web­site head for easy feed discovery)

via Zend Frame­work.

Tags: ,

1 Response to "Zend Framework — Reporting Potential Security Issues"

Leave a Comment

*

Get Adobe Flash player