E-Mail: security@hs-bremen.de
openPGP Key Download (ASC, 3 KB)
Fingerprint: 158A 20F8 C98F 0F65 3286 7CF2 08AE C4CB F681 FB11
The use of encrypted e-mail is recommended for the transmission of confidential information. Vulnerability reporters are requested to submit the report in PDF format to the above e-mail address.
Notes
A vulnerability report should be structured as follows:
- The name of the affected product and the vulnerability.
- A simple description (possibly screenshots or other images for better traceability) showing how the vulnerability was discovered (including any tools used).
- An assignment of the vulnerability to, for example, the OWASP Top 10 or the CVE. If none of the vulnerability categories fit, it should be described in more detail as "Other".
- A proof-of-concept code (PoC) or instructions showing how the vulnerability can be exploited.
- Include an (informal) declaration of consent for the inclusion of a name/alias in the University of Bremen's Hall of Fame.
- Include a risk assessment taking into account the technical circumstances to determine the severity of the vulnerability (e.g. by using a CVSS value and the associated matrix - preferably in the latest version).
- A description of the impact of the reported vulnerability or a threat model that describes a relevant attack scenario. If you have provided personal data in the message or e-mail, please note the information on data protection.