To report a vulnerability, please use GitHub Security Advisories. This is the primary and preferred way to report security issues in the omegaup project.
- Navigate to the Security tab on the repository.
- Click on Advisories.
- Click on Report a vulnerability (or follow the procedure described here).
- Detail the issue. See below for examples of information that might be useful to include.
The maintainers will acknowledge the receipt of the issue and review the report.
Make sure to include all the details that might help maintainers better understand and prioritize the vulnerability. For example, here is a list of details that might be worth adding:
- Versions of omegaup used and any other software involved.
- Detailed list of steps to reproduce the vulnerability.
- Consequences of the vulnerability.
- Severity you feel should be attributed to the vulnerability.
- Screenshots, logs, or any other relevant artifacts.
Feel free to extend the list above with everything else you think would be useful.
Once a maintainer has confirmed the relevance of the report, the draft security advisory will be used to discuss the issue with maintainers and the reporter(s).
If the vulnerability is accepted, a timeline for developing a patch, public disclosure, and patch release will be determined. The reporter(s) are expected to participate in the discussion of the timeline and abide by agreed-upon dates for public disclosure.
Vulnerabilities, once fixed, will be shared publicly as a GitHub Security Advisory and mentioned in the fixed versions' release notes.