mirror of
https://github.com/yogeshojha/rengine.git
synced 2026-09-28 12:44:57 +02:00
74 lines
4.9 KiB
Markdown
74 lines
4.9 KiB
Markdown
# Security Policy
|
|
[](https://huntr.dev/bounties/disclose/?target=https%3A%2F%2Fgithub.com%2Fyogeshojha%2Frengine)
|
|
|
|
Security Researchers, welcome onboard! I am excited to announce bug bounty program for reNgine in collaboration with [huntr.dev](https://huntr.dev), this means you'll be rewarded for any security vulnerabilities discovered in reNgine.
|
|
|
|
Thank you for your interest in reporting vulnerabilities to reNgine! If you are aware of potential security vulnerabilities within reNgine, we encourage you to report immediately via [huntr.dev](https://huntr.dev/bounties/disclose/?target=https%3A%2F%2Fgithub.com%2Fyogeshojha%2Frengine)
|
|
|
|
**Please do not disclose any vulnerabilities via Github Issues/Blogs/Tweets after/before reporting on huntr.dev as it is explicitly against huntr.dev and reNgine disclosure policy and will not be eligible for monetary rewards.**
|
|
|
|
Please note that the maintainer of reNgine does not determine the bounty amount.
|
|
The bounty reward is determined by industry-first equation from huntr.dev to understand the popularity, impact and value of repositories to the open source community.
|
|
|
|
**What do we expect from security researchers?**
|
|
|
|
* Patience: Please note that currently I am the only maintainer in reNgine and will take sometime to validate your report. I request your patience throughout the process.
|
|
* Respect Privacy and Security Reports: Please do not disclose any vulnerabilities in public (this also includes github issues) before or after reporting on huntr.dev! That is against the disclosure policy and will not be eligible for monetary rewards.
|
|
* Respect the rules
|
|
|
|
**What do I get in return?**
|
|
|
|
* Much thanks from Maintainer
|
|
* Monetary Rewards
|
|
* CVE ID(s)
|
|
|
|
Please find the [FAQ](https://www.huntr.dev/faq) and [Responsible disclosure policy](https://www.huntr.dev/policy/) from huntr.dev.
|
|
|
|
## Past Security Vulnerabilities
|
|
|
|
Thanks to these individuals for reporting Security Issues in reNgine.
|
|
|
|
### 2022
|
|
|
|
* [HIGH] [Blind command injection](https://huntr.dev/bounties/b255cf59-9ecd-4255-b9a2-b40b5ec6c572/) in CMS Detector, Reported by [Abdulrahman Abdullah](https://github.com/ph33rr)
|
|
|
|
* [HIGH] [Command Injection](https://huntr.dev/bounties/00e10ef7-ff5e-450f-84ae-88c793d1a607/) in via Proxy, Reported by [Koen Molenaar](https://github.com/k0enm)
|
|
|
|
* [HIGH] [Command Injection](https://huntr.dev/bounties/7f1f9abb-a801-444d-bd58-97e1c0b2ddb9/) in via YAML Engine, Reported by [Koen Molenaar](https://github.com/k0enm) and [zongdeiqianxing](https://github.com/zongdeiqianxing)
|
|
|
|
* [LOW] [Stored XSS](https://huntr.dev/bounties/dfd440ba-4330-413c-8b21-a3d8bf02a67e/) on Import Targets via filename, Reported by [Veshraj Ghimire](https://github.com/V35HR4J)
|
|
|
|
* [LOW] [Stored XSS](https://huntr.dev/bounties/8ea5d3a6-f857-45e4-9473-e4d9cb8f7c77/) on HackerOne Markdown template, Reported by [Smaran Chand](https://github.com/smaranchand) and [Ayoub Elaich](https://github.com/sicks3c)
|
|
|
|
* [LOW] [Stored XSS](https://huntr.dev/bounties/6e2b7f19-d457-4e05-b2d5-888110898147/) via Scan Engine Name, Reported by [nerrorsec](https://github.com/nerrorsec)
|
|
|
|
* [LOW] [HTML Injection](https://huntr.dev/bounties/da2d32a1-8faf-453d-8fa8-c264fd8d7806/) in Subscan, Reported by [nerrorsec](https://github.com/nerrorsec)
|
|
|
|
|
|
### 2021
|
|
* [LOW] [Stored XSS](https://github.com/yogeshojha/rengine/issues/178) on Detail Scan Page via Page Title Parameter, Reported by [omemishra](https://github.com/omemishra)
|
|
|
|
* [LOW] [Stored XSS](https://github.com/yogeshojha/rengine/issues/347) on Vulnerability Scan page via URL Parameter, Reported by [Arif Khan, payloadartist](https://twitter.com/payloadartist)
|
|
|
|
* [LOW] Several Instances of XSS in reNgine 1.0 (#460, #459, #458, #457, #456, #455), Reported by [Binit Ghimire](https://github.com/TheBinitGhimire)
|
|
|
|
* [LOW] [Stored XSS](https://huntr.dev/bounties/ac07ae2a-1335-4dca-8d55-64adf720bafb/) on GF Pattern via filename, Reported by [nerrorsec](https://github.com/nerrorsec)
|
|
|
|
* [LOW] [Stored XSS](https://huntr.dev/bounties/0f8de2a4-7590-48f1-a5af-1e2cab9f6e85/) on Delete Scheduled Task via Scan Engine Name, Reported by [nerrorsec](https://github.com/nerrorsec)
|
|
|
|
* [LOW] [Stored XSS](https://huntr.dev/bounties/693a7d23-c5d4-448e-bbf6-50b3f0ad8544/) on Target Summary via Todo, Reported by [TheLabda](https://github.com/thelabda)
|
|
|
|
* [LOW] [Stored XSS](https://huntr.dev/bounties/81c48a07-9cb8-4da8-babc-28a4076a5e92/) on Nuclei Template Summary via maliclous Nuclei Template, Reported by [Walleson Moura](https://github.com/phor3nsic)
|
|
|
|
* [MEDIUM] [Path Traversal/LFI](https://huntr.dev/bounties/5df1a485-7a1e-411d-9664-0f4343e8512a/), reported by [Koen Molenaar](https://github.com/k0enm)
|
|
|
|
|
|
|
|
|
|
|
|
**reNgine thanks the following people for making a responsible disclosure and helping the community make reNgine safer!**
|
|
|
|
* [onemishra](https://github.com/omemishra)
|
|
* [Arif Khan, payloadartist](https://twitter.com/payloadartist)
|
|
* [Binit Ghimire](https://github.com/TheBinitGhimire)
|