Skip to content

Security: apache/roller

Security

SECURITY.md

Security policy

Reporting a vulnerability

Report suspected security vulnerabilities in Apache Roller privately to the Apache Security Team at [email protected]. Please do not report them in the public issue tracker, in GitHub issues or pull requests, or on the public mailing lists.

A useful report says which Roller version you tested, how the site is configured in any way that matters to the issue, and what steps reproduce the behaviour. If you are not sure whether what you found is a vulnerability, report it privately anyway and we will work it out with you.

The Apache Security Team forwards the report to the Roller PMC. See the ASF security page for the foundation-wide process.

Security model

The Roller security model explains who Roller trusts, what each kind of user may do, and what counts as a vulnerability. Please read it before you report.

Supported versions

Security fixes are made on the current release line and shipped in a new release. Older releases are not patched. If you run an older version, upgrade to the current release.

Advisories

Advisories are listed at https://roller.apache.org/security.html.

There aren't any published security advisories