The BSVS leaders and community take all security bugs seriously. We appreciate your efforts to disclose issues responsibly, and will make every effort to acknowledge your contributions.
We aim to reply within 3 days of receiving your finding. If a finding is accepted, we aim to publish a patch within 6 days. If it is declined, we will reply to let you know.
Email jerry@owasp.org with the following information:
- Name / affiliation
- Vulnerability description
- Steps to reproduce the issue
- Current public knowledge of this vulnerability (e.g. related CVE, security advisory, etc.)
Acknowledgments are listed in the Hall of Fame.