Responsible Disclosure
Vulnerability Reporting
Report potential JKSolutions security vulnerabilities privately and with enough information for investigation.
Reporting a vulnerability
Send security reports privately to JKSolutions through the published contact channel and clearly identify the report as security-related.
Useful report content
- Affected product and version.
- Affected page, endpoint or component.
- Required preconditions.
- Steps to reproduce.
- Observed impact.
- Relevant non-sensitive logs or screenshots.
Sensitive material
Do not send passwords, private keys, unrelated customer data or production secrets unless specifically requested through an appropriate secure channel.
Responsible publication
Avoid publishing exploit details before JKSolutions has had a reasonable opportunity to assess and remediate a valid report.