Security

Apache Roller Security

Reporting a vulnerability

Report suspected security vulnerabilities in Apache Roller privately to the Apache Security Team at security@apache.org. Please do not report them in the public issue tracker, in GitHub issues or pull requests, or on the public mailing lists.

A useful report says which Roller version you tested, how the site is configured in any way that matters to the issue, and what steps reproduce the behaviour. If you are not sure whether what you found is a vulnerability, report it privately anyway and we will work it out with you.

The Apache Security Team forwards the report to the Roller PMC, and coordination continues on a private list. See the ASF security page for the foundation-wide policy that governs this process.

Security model

The Roller security model explains who Roller trusts, what each kind of user may do, the boundaries Roller keeps, and what is out of scope. Please read it before you report an issue.

What happens next

We acknowledge the report, investigate it, and tell you whether we accept it. Accepted reports get a CVE identifier, a fix, and a release. We ask reporters to keep the details private until the fix is released, and we credit reporters in the advisory unless they prefer otherwise.

Advisories are published when the fixed release is publicly available for download. They go to announce@apache.org, the Roller dev and user lists, and oss-security.

Supported versions

Security fixes are made on the current release line and shipped in a new release. Older releases are not patched in place. If you are running an older version, the fix is to upgrade to the current release.

Published advisories

Advisories for Apache Roller are announced on the lists above and archived at lists.apache.org.