@@ -12,62 +12,20 @@ Create a Vulnerability Report
12
12
13
13
If you believe you have discovered a vulnerability in MongoDB products
14
14
or have experienced a security incident related to MongoDB products,
15
- please report the issue to aid in its resolution.
15
+ please report the issue to aid in its resolution. For more information on
16
+ vulnerability reports, see the following resources:
16
17
17
- To report an issue, we strongly suggest filing a ticket in the
18
- :issue:`SECURITY <SECURITY>` project in JIRA. MongoDB, Inc
19
- responds to vulnerability notifications within 48 hours.
20
-
21
- Create the Report in JIRA
22
- -------------------------
23
-
24
- `Submit a Ticket
25
- <https://jira.mongodb.org/secure/CreateIssue!default.jspa?project-field=%22Security%22>`_
26
- in the :issue:`Security <SECURITY>` project on our JIRA.
27
- The ticket number will become the reference identification for the
28
- issue for its lifetime. You can use this identifier for tracking
29
- purposes.
30
-
31
- Information to Provide
32
- ----------------------
33
-
34
- All vulnerability reports should contain as much information
35
- as possible so MongoDB's developers can move quickly to resolve the issue.
36
- In particular, please include the following:
37
-
38
- - The name of the product.
39
-
40
- - *Common Vulnerability* information, if applicable, including:
41
-
42
- - CVSS (Common Vulnerability Scoring System) Score.
43
-
44
- - CVE (Common Vulnerability and Exposures) Identifier.
45
- - Contact information, including an email address and/or phone number,
46
- if applicable.
47
-
48
-
49
- Send the Report via Email
50
- -------------------------
51
-
52
- While JIRA is the preferred reporting method, you may also report
53
- vulnerabilities via email to `
[email protected]
54
-
55
-
56
- You may encrypt email using MongoDB's public key at
57
- `https://docs.mongodb.com/10gen-security-gpg-key.asc <https://docs.mongodb.com/10gen-security-gpg-key.asc>`_.
58
-
59
- MongoDB, Inc. responds to vulnerability reports sent via
60
- email with a response email that contains a reference number for a JIRA ticket
61
- posted to the :issue:`SECURITY` project.
18
+ * `MongoDB Security information <https://www.mongodb.com/security>`__ on our website
19
+ * `Webform <https://www.mongodb.com/bug-submission-form>`__ for vulnerability report submission
62
20
63
21
Evaluation of a Vulnerability Report
64
22
------------------------------------
65
23
66
- MongoDB, Inc. validates all submitted vulnerabilities and uses Jira
67
- to track all communications regarding a vulnerability,
68
- including requests for clarification or additional information. If
69
- needed, MongoDB representatives set up a conference call to exchange
70
- information regarding the vulnerability .
24
+ MongoDB, Inc. validates all submitted vulnerabilities through internal
25
+ investigation. If needed, MongoDB representatives will reach out to the
26
+ reporter for further information and to provide the results of the
27
+ investigation. Please allow MongoDB representatives up to one week to
28
+ acknowledge submissions .
71
29
72
30
Disclosure
73
31
----------
0 commit comments