We take security issues in Blueshell seriously. If you discover a vulnerability, please report it responsibly rather than disclosing it publicly.
Please email security concerns to: board@blueshell.utwente.nl
In your report, please include:
- A description of the vulnerability
- Steps to reproduce (if applicable)
- Potential impact
- Any suggested fix (optional)
We will acknowledge your report within 2 business days and aim to provide an initial assessment within 1 week.
Security updates will be provided for:
- The current version on the
mainbranch - Previous stable releases where practical
- We request that you do not publicly disclose the vulnerability until we have had reasonable time to develop and release a fix
- Typically, we aim to release security fixes within 2-4 weeks of notification
- We will provide you with a timeline and may work with you on coordinating responsible disclosure
See our README.md for an overview of our security measures, including:
- JWT authentication
- SQL injection prevention
- XSS protection
- CORS restrictions
- TLS encryption