Skip to content

Commit

Permalink
Suggested paragraph re known issues
Browse files Browse the repository at this point in the history
  • Loading branch information
sebbASF committed Jun 10, 2024
1 parent 0f7945e commit ad64909
Showing 1 changed file with 14 additions and 0 deletions.
14 changes: 14 additions & 0 deletions content/security/index.md
Original file line number Diff line number Diff line change
Expand Up @@ -39,6 +39,20 @@ Please send one plain-text, unencrypted, email for each vulnerability you are re
ask you to resubmit your report if you send it as an image, movie, HTML, or
PDF attachment when you could as easily describe it with plain text.

## Issues not considered as security vulnerabilities {#known-issues}

These are things that we are well aware of, and have been reported to us many
times, but we do not class as a security vulnerability.
Please do not report them.

Issues not classed as security relevant:

- A lack of DMARC or SPF record on our domains
- "Clickjacking" on our domains
- Directory listings. These are deliberate and do not contain sensitive information
- Systems that disclose the versions of the servers and software we use
- Data that is publically accessible in our JIRA bug tracking system

## Vulnerability Information

You can usually find information on known vulnerabilities for an Apache project on the project's web pages. For convenience, consult the [list of
Expand Down

0 comments on commit ad64909

Please sign in to comment.