15 Star 76 Fork 22

Gitee 极速下载 / Matomo

加入 Gitee
与超过 1200万 开发者一起发现、参与优秀开源项目,私有仓库也完全免费 :)
免费加入
此仓库是为了提升国内下载速度的镜像仓库,每日同步一次。 原始仓库: https://github.com/matomo-org/matomo
克隆/下载
SECURITY.md 1.83 KB
一键复制 编辑 原始数据 按行查看 历史
Matthieu Aubry 提交于 2021-02-15 11:59 . Update SECURITY.md (#17214)

Reporting Security Issues

Security Bug Bounty Program

The Matomo Security Bug Bounty Program is designed to encourage security research in Matomo software and to reward those who help us create the safest web analytics platform.

Critical security issues will be rewarded up to 5,000 USD. Critical issue in Matomo means an issue in our latest official release at: https://builds.matomo.org/latest.zip as installed on a typical server (and possibly using any of our official plugins by Matomo or InnoCraft from the Marketplace). If you can gain remote code execution on the server (i.e. RCE), or if you're able to delete data with an HTTPS request (i.e. SQL Injection), this may qualify as a Critical issue.

(Note: If a Remote Code Execution (RCE) is only available when logged in as a Super User, the issue will qualify as "High" and not "Critical".)

High security issues that can cause a direct attack (CSRF, XSS, Auth bypass, etc.) will be rewarded with up to 777 USD.

Other issues will typically be rewarded by 242 USD (or more or less depending on the impact.)

Responsible disclosure by email

We encourage you to responsibly report issues via our Matomo Bug Bounty Program on HackerOne or you can also email us at security@matomo.org.

If you have found a security issue in Matomo please read our security notes regarding responsible disclosures.

Improve your Matomo Server Security

Secure Matomo server: follow these steps to keep your Matomo data safe.

Security announcements

Please subscribe to the Changelog (rss feed) to be notified of new releases (including security releases).

1
https://gitee.com/mirrors/Matomo.git
git@gitee.com:mirrors/Matomo.git
mirrors
Matomo
Matomo
4.x-dev

搜索帮助