| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Before you report a vulnerability, first take the following steps:
If you have completed the above steps and confirmed that the security policy does not address the vulnerability, report the vulnerability as a security advisory. Please include the following information:
Once a vulnerability is reported we will take the following steps:
flowchart TD
START([Report received]) --> VALIDATE{Validate vulnerability within 7 days}
VALIDATE -->|Invalid| CLOSE([Close advisory])
VALIDATE -->|Valid| DRAFT([Accept as draft])
DRAFT --> ASSESS{Assess severity}
subgraph severity [" "]
NONE["None<br/><br/><br/> "]
LOW["Low<br/><br/>Disclosed in:<br/>14 days"]
MEDIUM["Medium<br/><br/>Disclosed in:<br/>14 days"]
HIGH["High<br/><br/>Disclosed in:<br/>7 days"]
CRITICAL["Critical<br/><br/>Disclosed in:<br/>48 hours"]
end
ASSESS --> NONE
ASSESS --> LOW
ASSESS --> MEDIUM
ASSESS --> HIGH
ASSESS --> CRITICAL
NONE --> CLOSE
LOW --> UPDATE
MEDIUM --> CVE([Request CVE])
HIGH --> CVE
CRITICAL --> CVE
CVE --> NOTIFY([Notify eligible sponsors])
NOTIFY --> UPDATE([Update draft advisory])
UPDATE --> PATCH([Create patch])
PATCH --> RELEASE([New release])
RELEASE --> PUBLISH([Publish advisory])
PUBLISH -.-> DISCLOSE([Reporter disclosure])
style DISCLOSE stroke-dasharray: 7
CVE requests: Reporters should not request or assign a CVE. After validating a report, ImageMagick maintainers will determine whether a CVE is appropriate and request one when warranted.
Timelines: The timelines in the incident response plan are targets, not guarantees. Actual remediation dates may vary depending on the complexity of the vulnerability and maintainer availability.
| Back | FazBrowse Home | New Git URL |