SpnManager/disclosure
Kerberos broken now? →
security vulnerability disclosure

Report a vulnerability.

How to report, what to expect, and what is safe to test.

01

How to report

Email {{ tok.SECURITY_EMAIL }}. PGP key: {{ tok.SECURITY_PGP_FINGERPRINT }}. Include the module version, a reproduction, and impact as you understand it.

02

What to expect

Acknowledgement within {{ tok.DISCLOSURE_ACK_TARGET }}. Status updates every {{ tok.DISCLOSURE_UPDATE_CADENCE }}. Fix or mitigation target: {{ tok.DISCLOSURE_FIX_TARGET }}.

03

In scope

The SpnManager module and C# engine, this website, the evidence-pack signing process.

04

Out of scope

Azure Marketplace and AWS Marketplace platforms (report to them). Your own Active Directory. Denial of service against this website.

05

Safe harbour

{{ tok.SAFE_HARBOUR_TEXT }}

06

Credit

Reporters are credited in the release notes if they wish. {{ tok.BOUNTY_POLICY }}