11# Security Policy
22
3- [ Security] ( https://nextcloud.com/security/ ) is very important to us.
3+ [ Security] ( https://nextcloud.com/security/ ) is very important to us.
44
5- If you believe you have found a security vulnerability that meets our definition of a security
5+ If you believe you have found a security vulnerability that meets our definition of a security
66vulnerability, please report is as described below.
77
88## Context
99
10- Please review our [ threat model and accepted risks] ( https://nextcloud.com/security/threat-model ) to learn what
11- is currently considered a security vulnerability versus expected behavior. And review what is considered
10+ Please review our [ threat model and accepted risks] ( https://nextcloud.com/security/threat-model ) to learn what
11+ is currently considered a security vulnerability versus expected behavior. And review what is considered
1212[ in scope or bounty eligible] ( https://hackerone.com/nextcloud/policy_scopes ) .
1313
1414
@@ -31,13 +31,17 @@ Your report should include:
3131
3232You should receive an initial acknowledgement within 24 hours in most cases.
3333
34- A member of the security team will confirm the vulnerability, determine its impact, follow-up with any questions,
34+ A member of the security team will confirm the vulnerability, determine its impact, follow-up with any questions,
3535and coordinate the fix and publication.
3636
3737The fix will be applied to all applicable and still supported stable branches, tested, and packaged in the next security release.
3838The vulnerability will be publicly announced after the release. Finally, your name will be added
39- to the [ hall of fame] ( https://hackerone.com/nextcloud/thanks ) as a thank you from the entire Nextcloud
40- community.
39+ to the [ hall of fame] ( https://hackerone.com/nextcloud/thanks ) as a thank you from the entire Nextcloud
40+ community.
41+
42+ If the vulnerability involves an app that is not maintained by Nextcloud (i.e. hosted by the
43+ Nextcloud project but community maintained, or hosted elsewhere), the security team will try to coordinate with the
44+ current maintainer and help to get the issue fixed in similar fashion.
4145
4246### Bug Bounties
4347
@@ -47,8 +51,7 @@ on past bounty ranges can be found at [hackerone.com/nextcloud](https://hackeron
4751## Existing Security Advisories
4852
4953Published security advisories for the Nextcloud Server, Clients and Apps can be viewed at
50- [ https://github.com/nextcloud/security-advisories/security/advisories ] (https://github.com/nextcloud/security-advisories/security/advisories
51- ).
54+ [ https://github.com/nextcloud/security-advisories/security/advisories ] ( https://github.com/nextcloud/security-advisories/security/advisories ) .
5255
5356## Supported Versions
5457
0 commit comments