Skip to content

Security: datenschutz-individuell/twofactor_email

SECURITY.md

Security Policy

The security model is documented by audience — users, administrators, and developers — with a separate threat model. For how the app is built, see doc/architecture.md.

Supported Versions

We only support the latest released version of the app for any Nextcloud version that still has official (not extended) support.

Reporting a Vulnerability

You may create an issue in GitHub to report security vulnerabilities unless you think that it is not easily fixable and would affect many users. In this case, please email Olav directly using olav at seyfarth dot de. Olav's OpenPGP key 0x6AE1EF56 is available on the website as well as on the OpenPGP keyserver.

We will timely review your report and fix it if we know how and if it's not an upstream issue. Please provide contact details so that we may get in touch with you. Once we publish the fixed code, we would like to pay credits to you. So please also include details on how we shall mention you. See CONTRIBUTORS for examples.

Bounty

We cannot provide any bounty for reporting. But if you feel that it would affect many users or Nextcloud as a platform, you may use their channel to report it, see the security on the Nextcloud website. They used to use Hacker One as a reporting platform and provide a bounty if the report met their criteria. Due to too many AI generated reports, they abandoned it.

There aren't any published security advisories