18 lines
1.1 KiB
Markdown
18 lines
1.1 KiB
Markdown
# Security Policy
|
|
|
|
## Reporting a Vulnerability
|
|
|
|
Please DO NOT report any security issues to public GitHub issue.
|
|
|
|
Please DO report security vulnerabilities via the [Report Form](https://github.com/neutrinolabs/xrdp/security/advisories/new) so that we can fix the security problem to protect a lot of users around the world as soon as possible.
|
|
|
|
If you have anything else you want to report privately to developers, send us an email to the following email address. This is a private mailing list not open for public viewing. Do not send security reports to this address - it is private but not secure.
|
|
|
|
* [xrdp-core@googlegroups.com](mailto:xrdp-core@googlegroups.com)
|
|
|
|
## Handling of Duplicate Reports
|
|
|
|
Due to the high volume of vulnerability reports we receive, duplicate reports are handled on a first-come-first-served basis, even if discovered independently by different parties. Consequently, only the first reporter will be acknowledged in the public advisory.
|
|
|
|
As reports remain confidential until public disclosure, reporters may not know if they are the first to submit. We appreciate your understanding.
|