Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Discuss how we should address potential QGIS server security issues #40

Open
elpaso opened this issue May 15, 2020 · 1 comment
Open
Assignees
Labels

Comments

@elpaso
Copy link

elpaso commented May 15, 2020

Discussing with Matthias about a potential issue in QGIS Server where an expression can be used to disclose information about the server environment we came into the situation where we cannot publicly discuss about the issue because we don't have a patch or a mitigation procedure yet.

This made me think that we should have a standard procedure about how we address these cases, I don't have a proposal but I think that maybe we could have a reserved way to communicate with a restricted group of developers (security team) and perhaps even a dedicated budget for this kind of issue.

I'm thinking at a budget because it may happen that the patch (like in this case) is not trivial.

I remember we discussed something related to security disclosure in the past, maybe I just forgot about it and we do already have an established procedure, I apologize if that's the case.

@elpaso elpaso added the todo label May 15, 2020
@alexbruy
Copy link

There were a disscussion while ago http://osgeo-org.1560.x6.nabble.com/QGIS-Developer-Reporting-security-related-issues-td5429789.html. Not sure if this what you are looking for.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants