mirror of
https://github.com/Vateron-Media/XC_VM.git
synced 2026-10-04 12:02:33 +02:00
116 lines
3.6 KiB
YAML
116 lines
3.6 KiB
YAML
name: "Security Vulnerability Report"
|
|
description: "Report a security vulnerability. For critical issues, prefer private disclosure."
|
|
title: "[SECURITY]: "
|
|
labels: ["security", "bug"]
|
|
|
|
body:
|
|
- type: markdown
|
|
attributes:
|
|
value: |
|
|
## ⚠️ Important Notice
|
|
|
|
**This issue will be PUBLIC.** If the vulnerability is critical (RCE, auth bypass, data leak),
|
|
please consider reporting it privately instead:
|
|
- Use [GitHub Security Advisories](https://github.com/Vateron-Media/XC_VM/security/advisories/new)
|
|
|
|
Only use this form for lower-severity security issues that are safe to disclose publicly.
|
|
|
|
- type: checkboxes
|
|
id: disclosure_ack
|
|
attributes:
|
|
label: Disclosure Acknowledgment
|
|
options:
|
|
- label: "I understand this issue will be **publicly visible** and have confirmed it is safe to disclose."
|
|
required: true
|
|
- label: "I have searched existing issues and confirmed this is not a duplicate."
|
|
required: true
|
|
|
|
- type: input
|
|
id: version
|
|
attributes:
|
|
label: "Affected Version(s)"
|
|
description: "Which version(s) of XC_VM are affected? Comma-separate if multiple."
|
|
placeholder: "e.g. 2.0.1, 2.0.0"
|
|
validations:
|
|
required: true
|
|
|
|
- type: dropdown
|
|
id: severity
|
|
attributes:
|
|
label: "Severity (CVSS-like)"
|
|
description: "Estimate the severity of this vulnerability."
|
|
options:
|
|
- "Critical — RCE, authentication bypass, full data access"
|
|
- "High — privilege escalation, significant data exposure"
|
|
- "Medium — limited data exposure, requires authentication"
|
|
- "Low — information disclosure, minimal impact"
|
|
validations:
|
|
required: true
|
|
|
|
- type: dropdown
|
|
id: affected_component
|
|
attributes:
|
|
label: "Affected Component"
|
|
description: "Which part of the system is affected?"
|
|
options:
|
|
- "Authentication / Authorization"
|
|
- "Admin Panel"
|
|
- "Player API"
|
|
- "Reseller API"
|
|
- "Streaming Engine"
|
|
- "Nginx Configuration"
|
|
- "Database"
|
|
- "File System / Permissions"
|
|
- "Other"
|
|
validations:
|
|
required: true
|
|
|
|
- type: textarea
|
|
id: vulnerability_description
|
|
attributes:
|
|
label: "Describe the Vulnerability"
|
|
description: "Provide a clear and concise description. Do NOT include working exploits for critical issues."
|
|
placeholder: "What is the issue? What could an attacker achieve?"
|
|
validations:
|
|
required: true
|
|
|
|
- type: textarea
|
|
id: reproduction_steps
|
|
attributes:
|
|
label: "Steps to Reproduce"
|
|
description: "Minimal steps to demonstrate the vulnerability."
|
|
placeholder: |
|
|
1. Go to...
|
|
2. Send request...
|
|
3. Observe...
|
|
validations:
|
|
required: true
|
|
|
|
- type: textarea
|
|
id: expected_behavior
|
|
attributes:
|
|
label: "Expected Behavior"
|
|
description: "What should happen if the vulnerability did not exist?"
|
|
validations:
|
|
required: true
|
|
|
|
- type: textarea
|
|
id: impact
|
|
attributes:
|
|
label: "Impact Assessment"
|
|
description: "Describe the potential real-world impact (data loss, unauthorized access, service disruption)."
|
|
validations:
|
|
required: true
|
|
|
|
- type: textarea
|
|
id: suggested_fix
|
|
attributes:
|
|
label: "Suggested Fix"
|
|
description: "If you have a proposed fix or mitigation, describe it here."
|
|
|
|
- type: textarea
|
|
id: additional_information
|
|
attributes:
|
|
label: "Additional Information"
|
|
description: "Environment details, configurations, related CVEs, etc."
|