Table of Contents

Security

This document describes how security incidents are handled since Flyspray 0.9.9.

Reporting and handling security problems.

  1. is remotely exploitable, such as XSS(and friends), remote code execution or SQL Injection.
  2. it discloses critically sensitive user information (passwords, the contents of other files in the system..).
  3. All other type of issues considered 'minor' will be fixed in the next patch level release in conjunction with other bugs.

Flyspray 0.9.9

Security problems archive

You can read a list of known security problems on Flsypray's Secunia.com page

Things that are NOT security holes in Flyspray

PHP security holes, where the only real solution is to upgrade your PHP version to be protected.

Also, There are a few third party flyspray integrations that we are aware of :

Please do not contact us about vulnerabilities in that products, unless the problem is present in officially supported Flyspray releases available in either the download section or in the active branches of our SVN repository.

We have no control of the code included in that tools.