docs/docs/policies/security-disclosure.mdx
This page describes the Hasura security vulnerability reporting and disclosure process.
Join the Hasura Security Announcements group for emails about security announcements.
We’re extremely grateful for security researchers and users who report vulnerabilities to the Hasura community. All reports are thoroughly investigated by the Hasura team.
To report a security issue, please email us at [email protected] with the vulnerability details, and attach the relevant information including screenshots/videos. The more details we have, the quicker will we be able to fix any potential vulnerabilities.
Hasura does not provide monetary reward for vulnerability disclosures however, at our sole discretion, we may make exceptions to this policy for exceptional contributions.
You may be eligible for a reward if it requires a severe code/configuration change from our side. The rewards can be both monetary or swag.
Please reference our guidance at the bottom of the page for the types of vulnerabilities that are in and out-of-scope.
Do not use social engineering techniques and make a good faith effort to avoid any privacy violations, destruction of data, and interruption or degradation of our service.
If you should accidentally do any of these things, please stop immediately and report the issue.
In these cases you can join our Discord server where the community will be happy to help you out.
Each vulnerability report is acknowledged and analyzed by the Hasura team within 3 working days.
The reporter will be kept updated at every stage of the issue’s analysis and resolution (triage -> fix -> release).
A public disclosure date in case a vulnerability is discovered is negotiated by the Hasura team and the bug submitter.
We prefer to fully disclose the vulnerability as soon as possible once a user mitigation is available and enough of the affected instances have been upgraded.
It is reasonable to delay disclosure when the vulnerability or the fix is not yet fully understood, the solution is not well-tested, or for vendor coordination. The time frame for disclosure is from immediate (especially if the vulnerability is already publicly known) to a few weeks. Though, we expect the time frame between a report to a public disclosure to typically be in the order of 7 days.
In any case, the Hasura team will do their best to identify and fix any vulnerabilities as soon as possible, as well as communicate to the submitter about the progress and set a disclosure date.
We are keen on hearing about the vulnerabilities encompassing the following categories:
When reporting vulnerabilities, please consider (1) attack scenario / exploitability, and (2) security impact of the bug. The following issues are considered out of scope: