rails/rails-html-sanitizer

Private reporting of a potential security vulnerability

Sim4n6 opened this issue · 6 comments

Dear rails-html-sanitizer team,

I have identified a security vulnerability in the codebase of the latest version of rails-html-sanitizer.

I would like to report it privately. Could you please consider opting-in the new Github feature for private reporting.

Kind consideration
@Sim4n6

Hi! Thanks for asking about our security policy. It's documented in the README:

image

Because this project is under the Rails umbrella, you should report security concerns following this policy: https://rubyonrails.org/security

We use Hackerone, here's the deeplink: https://hackerone.com/rails

Thank you for your response.

Sorry about that, but I'm a bit lost.

Do you suggest please that I initially submit the report via https://hackerone.com/rails?type=team or do I proceed via https://hackerone.com/ibb?type=team , please ?

Regards,
@Sim4n6

I'm going with https://hackerone.com/rails?view_policy=true right away 👍🏾

Thank you.