Create Vulnerability Reporting Contact #17

Open
opened 2026-07-23 16:26:02 +00:00 by thebeanogamer · 9 comments
Member

For the policy on #14, we need somewhere private for users to submit reports to. Right now the docs just say to email RH ProdSec.

I'd strongly prefer this goes to the same place as #13, and I think @agk's suggestion would work (#13 (comment)). Maybe that looks like a new Product (Fedora Security) within the existing Fedora Classification, with one component for Package Vulnerabilities and another for Platform Vulnerabilities.

Membership of the former group can be answered on #13, for the latter group I think we put a few Security people and a few Infra people in there to triage any reports.

An email address would be nice, although from experience they do tend to get spammed a bit so maybe we force people to raise it through Bugzilla.

For the policy on #14, we need somewhere private for users to submit reports to. Right now the docs just say to email RH ProdSec. I'd strongly prefer this goes to the same place as #13, and I think @agk's suggestion would work (https://forge.fedoraproject.org/security/tickets/issues/13#issuecomment-1060903). Maybe that looks like a new Product (Fedora Security) within the existing Fedora Classification, with one component for Package Vulnerabilities and another for Platform Vulnerabilities. Membership of the former group can be answered on #13, for the latter group I think we put a few Security people and a few Infra people in there to triage any reports. An email address would be nice, although from experience they do tend to get spammed a bit so maybe we force people to raise it through Bugzilla.
Owner

Just fyi, I am not sure your scope here (packages? forge projects? everything?), but infra has:

https://admin.fedoraproject.org/.well-known/security.txt

for infrastructure applications/security issues.

Just fyi, I am not sure your scope here (packages? forge projects? everything?), but infra has: https://admin.fedoraproject.org/.well-known/security.txt for infrastructure applications/security issues.
Author
Member

@kevin the context was a discussion about CRA requirements and the need for somewhere to report vulnerabilities in Fedora infra.

Didn't know we already had an email for that, and am open to using that. Where does it go?

I think the policy on that page could do with some love, happy to help with that.

@kevin the context was a discussion about CRA requirements and the need for somewhere to report vulnerabilities in Fedora infra. Didn't know we already had an email for that, and am open to using that. Where does it go? I think the policy on that page could do with some love, happy to help with that.
Owner

Well, for "fedora Infra" I would think that file would be the place... for packages, projects/sigs, etc it may well be someplace else.

Right now that email is an alias that goes to a very few folks in our sysadmin-main group. When we get a report that needs work from others we pull them in. I would say most of the reports we were getting were just beg bounties, but we have gotten a few notable real issues in the past.

Sure, I threw together that page to try and slow the amount of beg bounties mostly, but happy to make changes/clean it up.

Well, for "fedora Infra" I would think that file would be the place... for packages, projects/sigs, etc it may well be someplace else. Right now that email is an alias that goes to a very few folks in our sysadmin-main group. When we get a report that needs work from others we pull them in. I would say most of the reports we were getting were just beg bounties, but we have gotten a few notable real issues in the past. Sure, I threw together that page to try and slow the amount of beg bounties mostly, but happy to make changes/clean it up.
Member

Also posting it here...

In case of a potential CRA reportable events reported to Fedora Infra Security, can you please pull me and @m-findra as well?
It's actually required under CRA Stewardship obligations to report these type of incidents to the SRP.
TLDR: We will do the heavy lifting, we just need to be pulled in.

Thank you

Also posting it here... In case of a potential CRA reportable events reported to Fedora Infra Security, can you please pull me and @m-findra as well? It's actually required under CRA Stewardship obligations to report these type of incidents to the SRP. TLDR: We will do the heavy lifting, we just need to be pulled in. Thank you
Owner

Well, I am open to doing that, but I would like to be very clear what your responsibilities are/what you plan to do?

I think there's also some confusion here in that the infra-security alias is for reporting fedora infrastructure security issues.
I don't think it should ever be used to report say security issues in packages fedora ships or some kind of security issue in some deliverable fedora produces. Just infrastructure things like our download servers, applications like pagure/forgejo/mirrormanager/koji/etc...

So for example, a report about a vulnerability in some thing we have deployed or caused by the configuration we are using to deploy it. "I see that your webserver allows $foo, is that intended"

Does that make sense or add to confusion?

Well, I am open to doing that, but I would like to be very clear what your responsibilities are/what you plan to do? I think there's also some confusion here in that the infra-security alias is for reporting fedora infrastructure security issues. I don't think it should ever be used to report say security issues in packages fedora ships or some kind of security issue in some deliverable fedora produces. Just infrastructure things like our download servers, applications like pagure/forgejo/mirrormanager/koji/etc... So for example, a report about a vulnerability in some thing we have deployed or caused by the configuration we are using to deploy it. "I see that your webserver allows $foo, is that intended" Does that make sense or add to confusion?
Member

Our responsibilities are to determine if the incident (in this case since it's infra problems) meets the criteria for the Severe incident under CRA and thus is reportable.
Once we determine this we do the reporting (first 24h, second 72h, and final 30d). We'll need to be kept in loop as every report mandates more and more information. You can check what will be required to report under Q16: https://www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp/frequently-asked-questions

As I mentioned the reports you receive are only tied to the CRA Incident category. The CRA vulnerability category is cover by the fact that we do VM for Fedora and if we come across a vulnerability that's reportable under CRA we'll do the round of reports as well.

Does that answer your questions?

Our responsibilities are to determine if the incident (in this case since it's infra problems) meets the criteria for the `Severe incident` under CRA and thus is reportable. Once we determine this we do the reporting (first 24h, second 72h, and final 30d). We'll need to be kept in loop as every report mandates more and more information. You can check what will be required to report under Q16: https://www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp/frequently-asked-questions As I mentioned the reports you receive are only tied to the CRA Incident category. The CRA vulnerability category is cover by the fact that we do VM for Fedora and if we come across a vulnerability that's reportable under CRA we'll do the round of reports as well. Does that answer your questions?
Owner

ok, that does help for sure.

Ideally I just want infra related reports to the infra-security alias (but of course I can't control who sends what). :)

Instead of adding you specifically, perhaps it would be worthwhile to add a role based alias that you could control?
ie, 'fedora-cra-stewards@' or something? That way we won't need to adjust it on our side and it would be clear where it's going?

but fine to just add you if you want to keep it simple.

ok, that does help for sure. Ideally I just want infra related reports to the infra-security alias (but of course I can't control who sends what). :) Instead of adding you specifically, perhaps it would be worthwhile to add a role based alias that you could control? ie, 'fedora-cra-stewards@' or something? That way we won't need to adjust it on our side and it would be clear where it's going? but fine to just add you if you want to keep it simple.
Member

Please forward it to secalert@redhat.com. Our team is closely monitoring it

Please forward it to secalert@redhat.com. Our team is closely monitoring it
Owner

ok. added.

ok. added.
Sign in to join this conversation.
No labels
meeting
No milestone
No project
No assignees
3 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
security/tickets#17
No description provided.