Skip to content Skip to footer

Vulnerability disclosure policy

This vulnerability disclosure policy applies to any vulnerabilities you are considering reporting to us.
We recommend reading this vulnerability disclosure policy fully before you report a vulnerability and always acting in compliance with it.
We do not offer a bug bounty program or monetary rewards for responsible disclosures. Compensation requests will not be considered in compliance with this vulnerability disclosure policy.
If you are an AGH University employee or PHD student please contact with the Centre for Information Security before you take any actions which are included to this document.

Testing vulnerabilities

We highly recommend reporting all discovered vulnerabilities to help us ensure the highest level of security for our systems and services.
Please report any vulnerability to the Centre for Information Security at the AGH University of Krakow.
You can report any vulnerability you discover in our systems by emailing us at security@agh.edu.pl. We recommend sending the report using PGP.

-----BEGIN PGP PUBLIC KEY BLOCK-----
mDMEaG4R2hYJKwYBBAHaRw8BAQdAhjY+nQEU1k6RJIj4mpMOY/RfJJabdNyzdl0h
3wddck60I0NCSSBBR0ggPGJlenBpZWN6ZW5zdHdvQGFnaC5lZHUucGw+iJAEExYK
ADgWIQQ4pCezagcim05UUTPE1O/NWsosFQUCaG4R2gIbAwULCQgHAwUVCgkICwUW
AgMBAAIeBQIXgAAKCRDE1O/NWsosFfrTAQD87GmOnT8wAlCV3arnylrQTH27YWd/
1VUAJbjYC7tYKAD/X1ow4VqaUx5Ghw8D004AAJluW/sDXDMgkvoxLmhjGAq4OARo
bhHaEgorBgEEAZdVAQUBAQdAXiNGRrFgr8TfRACceiqYeQM3DP/4xg4+SqoJkaVX
33sDAQgHiHgEGBYKACAWIQQ4pCezagcim05UUTPE1O/NWsosFQUCaG4R2gIbDAAK
CRDE1O/NWsosFVI2AQC6t+RKLosj2KjWbsCnH1HRdM6idiP7Dt0zEcyMDF5rAgEA
0F8gP3WZw0dfJPqP23AGkuTvBOkSTauptRJCRPSBiw0=
=thFo
-----END PGP PUBLIC KEY BLOCK-----

To prove the detected vulnerability, please at least:

  • indicating the IP address from which the vulnerability test was conducted, this will allow effective verification of the logs,
  • describe in as much details as possible how the bug was discovered and the steps to reproduce it, such as taking screenshots of the gained access to the system and, if possible, documenting the various stages of the attack.

Discovering vulnerability

Our expectations:

  • Ethical and lawful conduct - Reporting the vulnerability must not be motivated by financial benefit or other gratification. Access granted to a part of the infrastructure or system cannot be used to break the law, including stealing data.
  • Respect for users' privacy - Contact us immediately if the discovered vulnerability allows you to gain access to or modify our resources, which might be used to violate the privacy of our users (especially sensitive data) or other individuals whose data is processed.
  • Cooperation - We will do our best to eliminate the discovered vulnerability as soon as possible. We may need additional information from you, so we would be grateful if we could contact you.

You must not:

  • break any applicable laws or regulations
  • perform modifications or actions resulting in the loss or leakage of data in our systems or services
  • disrupt our services or systems, use high-intensity invasive or destructive scanning tools to find vulnerabilities, or attempt any form of denial of service
  • use social engineering, conduct phishing attacks, or physically attack our staff or infrastructure
  • send spam

You must always comply with data protection rules and must not violate the privacy of our users. For example, it is strictly prohibited to share, redistribute, or fail to properly secure data retrieved from systems or services accessed via a discovered vulnerability.


What we will do?

After receiving your report, we will:

  • confirm receipt of your report within 7 calendar days
  • ask you for additional information if necessary
  • contact you upon analysis and confirmation of the vulnerability to let you know how long we expect the fix to take (our aim is to resolve vulnerabilities within 90 days, or sometimes faster, depending on their complexity)
  • release information about the issue to the public, if necessary, to help others determine whether they are affected by the vulnerability and what steps they need to take
  • notify you when the vulnerability has been fixed
  • review what went wrong and update our policies to prevent the occurrence of similar vulnerabilities in the future
  • refrain from taking legal action against you for accessing (or attempting to access) our systems, provided this policy is followed and you do not cause any damage
  • treat your report and personal data as confidential and not pass them on to any third parties without your permissi

Policy scope

The scope of the policy includes the agh.edu.pl domain and its subdomains with the ranges of IP addresses: 149.156.96.0/19 and 149.156.192.0/20.

Stopka