This vulnerability disclosure policy applies to any vulnerabilities you are considering reporting to us.
We recommend reading this vulnerability disclosure policy fully before you report a vulnerability and always acting in compliance with it.
We do not offer a bug bounty program or monetary rewards for responsible disclosures. Compensation requests will not be considered in compliance with this vulnerability disclosure policy.
If you are an AGH employee or PHD student please contact with Centre for Information Security before you take any actions which are included to this document.
We highly recommend to report all discovered vulnerabilities which help us to ensure the highest level of security of our systems and services.
Please report any vulnerability to Centre for Information Security at AGH University of Krakow.
You can report any vulnerability you discover in our systems by email us at security@agh.edu.pl. We recommend you send the report by using PGP.
-----BEGIN PGP PUBLIC KEY BLOCK----- mDMEaG4R2hYJKwYBBAHaRw8BAQdAhjY+nQEU1k6RJIj4mpMOY/RfJJabdNyzdl0h 3wddck60I0NCSSBBR0ggPGJlenBpZWN6ZW5zdHdvQGFnaC5lZHUucGw+iJAEExYK ADgWIQQ4pCezagcim05UUTPE1O/NWsosFQUCaG4R2gIbAwULCQgHAwUVCgkICwUW AgMBAAIeBQIXgAAKCRDE1O/NWsosFfrTAQD87GmOnT8wAlCV3arnylrQTH27YWd/ 1VUAJbjYC7tYKAD/X1ow4VqaUx5Ghw8D004AAJluW/sDXDMgkvoxLmhjGAq4OARo bhHaEgorBgEEAZdVAQUBAQdAXiNGRrFgr8TfRACceiqYeQM3DP/4xg4+SqoJkaVX 33sDAQgHiHgEGBYKACAWIQQ4pCezagcim05UUTPE1O/NWsosFQUCaG4R2gIbDAAK CRDE1O/NWsosFVI2AQC6t+RKLosj2KjWbsCnH1HRdM6idiP7Dt0zEcyMDF5rAgEA 0F8gP3WZw0dfJPqP23AGkuTvBOkSTauptRJCRPSBiw0= =thFo -----END PGP PUBLIC KEY BLOCK-----
To prove the detected vulnerability, please at least:
Our expectations:
You must not:
You must always comply with data protection rules and must not violate the privacy of our users. We do not agree, for example, share, redistribute or fail to properly secure data retrieved from the systems or services granted by discovered vulnerability.
After receiving your report, we will: