Responsible Disclosure
Content
- Your responsible disclosure
- What we promise
- Qualified reporting of vulnerabilities
- Non-Qualified reporting of vulnerabilities
Disclose your finding responsible
If you discover vulnerabilities in the IT systems and web applications of the Fulda University of Applied Science, please inform us. We will then take immediate action to remedy the vulnerability as quickly as possible.
Your responsible disclosure
- Before reporting, please refer to the section “Non-qualified vulnerabilities” for information on cases that do not fall within the scope of our Responsible Disclosure Policy and will not be processed within this framework.
- Send your findings regarding the security issue by email to it-sicherheit@hs-fulda.de.
- Do not exploit the vulnerability or issue by, for example, downloading, uploading, modifying, or deleting data or executing code.
- Do not disclose information about the vulnerability to third parties or institutions.
- Do not carry out attacks on our IT systems that compromise, alter, or manipulate the infrastructure.
- Do not carry out social engineering (e.g., phishing), (distributed) denial of service, spam, or other attacks on the Fulda University of Applied Science.
- Provide us with sufficient information so that we can reproduce and analyze the problem. Please also provide a contact option for any queries.
- Unfortunately, we cannot offer any financial rewards (bug bounty).
As a rule, the address or URL of the affected system and a description of the vulnerability are sufficient. However, complex vulnerabilities may require further explanation and documentation.
What we promise
- You will receive automatic confirmation from us that we have received your report.
- If your report is deemed valid, you will also receive feedback on your report.
- We will treat your report confidentially and will not disclose your personal data to third parties without your consent.
- Reports received will be assessed based on their content and not on the age, education, gender, origin, or social status of the person reporting.
- If desired, we can issue a letter of thanks for qualified vulnerabilities.
Qualified reporting of vulnerabilities
Vulnerabilities whose exploitation could compromise the systems of the University of Stuttgart and where damage is likely to occur are referred to as qualified vulnerabilities.
Typical examples include cross-site scripting (XSS), remote code execution (RCE), or unauthorized access to properties or accounts.
Qualified reports are also characterized by the fact that
- we can verify the vulnerability,
- this is the first report of this vulnerability,
- the report contains a good and realistic attack scenario for the vulnerability, and
- we assess the finding as a real risk to the university’s systems or users.
In the case of a qualified report, you will always receive feedback on your report.
Non-qualified vulnerabilities
The following vulnerabilities and IT security gaps do not fall within the scope of the Fulda University of Applied Sciences’s Responsible Disclosure Policy:
- Misconfigurations that have the potential to lead to information leaks but do not contain any relevant data at the time of reporting.
- Forms with missing CSRF tokens.
- Missing security headers that do not directly lead to an exploitable vulnerability.
- The use of a library known to be vulnerable or publicly known to be broken (without active proof of exploitability).
- Social engineering against individuals or institutions at the University.
- (Distributed) denial-of-service attacks.
- Bots, SPAM, or mass registration.
- Violations of best practices (e.g., certificate pinning, security header).
- Use of vulnerable and “weak” cipher suites/ciphers.
This list is not exhaustive. If you report a non-qualified vulnerability to us, you will not receive any further feedback other than the automated confirmation of receipt.