This vulnerability disclosure policy applies to any vulnerabilities you are considering reporting to us.
We recommend reading this vulnerability disclosure policy fully before you report a vulnerability and always acting in compliance with it.
We do not offer a bug bounty program or monetary rewards for responsible disclosures. Compensation requests will not be considered in compliance with this vulnerability disclosure policy.
If you are an AGH University employee or PHD student please contact with the Centre for Information Security before you take any actions which are included to this document.
We highly recommend reporting all discovered vulnerabilities to help us ensure the highest level of security for our systems and services.
Please report any vulnerability to the Centre for Information Security at the AGH University of Krakow.
You can report any vulnerability you discover in our systems by emailing us at security@agh.edu.pl. We recommend sending the report using PGP.
-----BEGIN PGP PUBLIC KEY BLOCK----- mDMEaG4R2hYJKwYBBAHaRw8BAQdAhjY+nQEU1k6RJIj4mpMOY/RfJJabdNyzdl0h 3wddck60I0NCSSBBR0ggPGJlenBpZWN6ZW5zdHdvQGFnaC5lZHUucGw+iJAEExYK ADgWIQQ4pCezagcim05UUTPE1O/NWsosFQUCaG4R2gIbAwULCQgHAwUVCgkICwUW AgMBAAIeBQIXgAAKCRDE1O/NWsosFfrTAQD87GmOnT8wAlCV3arnylrQTH27YWd/ 1VUAJbjYC7tYKAD/X1ow4VqaUx5Ghw8D004AAJluW/sDXDMgkvoxLmhjGAq4OARo bhHaEgorBgEEAZdVAQUBAQdAXiNGRrFgr8TfRACceiqYeQM3DP/4xg4+SqoJkaVX 33sDAQgHiHgEGBYKACAWIQQ4pCezagcim05UUTPE1O/NWsosFQUCaG4R2gIbDAAK CRDE1O/NWsosFVI2AQC6t+RKLosj2KjWbsCnH1HRdM6idiP7Dt0zEcyMDF5rAgEA 0F8gP3WZw0dfJPqP23AGkuTvBOkSTauptRJCRPSBiw0= =thFo -----END PGP PUBLIC KEY BLOCK-----
To prove the detected vulnerability, please at least:
Our expectations:
You must not:
You must always comply with data protection rules and must not violate the privacy of our users. For example, it is strictly prohibited to share, redistribute, or fail to properly secure data retrieved from systems or services accessed via a discovered vulnerability.
After receiving your report, we will: