Univention Security Policy

We encourage reporting security issues via encrypted email. We offer the security.txt , for more information see https://securitytxt.org, discovery mechanism and Web Key Directory (WKD) to obtain the public corresponding to the email address advertised there.

gpg --auto-key-locate clear,wkd,nodefault --locate-keys security[at]univention.de

Alternatively the key can be downloaded directly here.

We appreciate responsible disclosure for vulnerabilities that affect either our products Univention Corporate Server and UCS@school or our online web services.

A brief summary of the attack scenario helps us to assess the scope of a vulnerability. It helps to answer questions like

  • How can the vulnerability be exploited? A look at the CVSS Base Score Matrix (see e.g. https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator) may be helpful, to think about aspects like attack vector, privileges required etc.
  • Who would be able to exploit the particular vulnerability?

Thanks for taking these hints into consideration.

GPG keyID: 0x2A5E8D1842C305FF
Key fingerprint: 9858 ED38 DF00 78C0 1F09 2E51 2A5E 8D18 42C3 05FF

Security Policy Univention