Re: Security vulnerabilities affects core API authorization of gnu.org

2021-01-04 Thread Salah Mosbah via Gcc
Hi Jeff, Does gnu.org has a bug bounty program or reporting bugs reward policy? On Mon, Jan 4, 2021 at 6:06 PM Jeff Law wrote: > > > On 1/4/21 3:23 AM, Salah Mosbah via Gcc wrote: > > Hi Janus, > > > > How can I report some high impact security vulnerabilities that

Security vulnerabilities affects core API authorization of gnu.org

2021-01-04 Thread Salah Mosbah via Gcc
Hi Janus, How can I report some high impact security vulnerabilities that I have found on gnu.org web app? Also, does gnu.org has a bug bounty program or reporting bugs reward policy? The vulnerabilities that I have found affects the core API of gnu.org which allows unauthorized users to get acc