Reported a ZMS security issue to Athenz on Mar 23. Multiple follow-ups, still no acknowledgement.
@athenzio@CloudNativeFdn – could someone from the project/security team please take a look?
5 days since I first reported this and I still haven't received a response to my emails or my original post.
@timify – could someone from the team please take a look? I'm happy to share the details privately.
Hi @timify , I responsibly disclosed a security issue on May 16 with multiple followups. It's now been months without even a simple acknowledgment. A basic confirmation of receipt is standard practice for responsible disclosure. Could someone please respond from the team?
5 days since I first reported this privately, and I still haven't received an acknowledgement by email or here.
@jibble_ltd – could someone from the team please take a look? Happy to share the details privately.
Hi @jibble_ltd , I responsibly disclosed a security issue on March 29 with multiple followups. It's now been months without even a simple acknowledgment. A basic confirmation of receipt is standard practice for responsible disclosure. Could someone please respond from the team?
Hi @timify , I responsibly disclosed a security issue on May 16 with multiple followups. It's now been months without even a simple acknowledgment. A basic confirmation of receipt is standard practice for responsible disclosure. Could someone please respond from the team?
Hi @jibble_ltd , I responsibly disclosed a security issue on March 29 with multiple followups. It's now been months without even a simple acknowledgment. A basic confirmation of receipt is standard practice for responsible disclosure. Could someone please respond from the team?
Hi @jibble_ltd , I responsibly disclosed a security issue on March 29 with multiple followups. It's now been months without even a simple acknowledgment. A basic confirmation of receipt is standard practice for responsible disclosure. Could someone please respond from the team?
Hi @timify , I responsibly disclosed a security issue on May 16 with multiple followups. It's now been months without even a simple acknowledgment. A basic confirmation of receipt is standard practice for responsible disclosure. Could someone please respond from the team?
Following up because this is disappointing.
After my previous post, @Hubstaff asked me to DM my email so the security team could reach out. I did so immediately and even followed up again. Despite that, I've still received no email or update.
The least you can do is respond.
Hi @Hubstaff ,
I reported a security vulnerability on April 19 and was told to expect a response within 14 business days. It's been nearly two months with no update despite several follow-ups.
#Security#BugBounty#ResponsibleDisclosure
@Hubstaff hey @Hubstaff I already shared my email address, but I still haven't received any communication from the team. It has been at least a week now
Hi @Hubstaff ,
I reported a security vulnerability on April 19 and was told to expect a response within 14 business days. It's been nearly two months with no update despite several follow-ups.
#Security#BugBounty#ResponsibleDisclosure