Skip to content

Security: adminsyspro/proxcenter-ui

SECURITY.md

Security Policy

Supported Versions

Only the latest released version of ProxCenter receives security updates.

Version Supported
Latest
Older

Reporting a Vulnerability

Please do not open a public GitHub issue for security vulnerabilities.

If you discover a security vulnerability in ProxCenter, please report it responsibly by emailing:

security@proxcenter.io

Include as much detail as possible:

  • Description of the vulnerability
  • Steps to reproduce
  • Affected version(s)
  • Potential impact
  • Any suggested fix (optional)

Response Timeline

  • Acknowledgment: within 48 hours of your report
  • Status update: within 7 days with an initial assessment
  • Fix: as soon as possible depending on severity

Disclosure Policy

We follow a responsible disclosure process:

  1. The vulnerability is reported privately via email
  2. Our team investigates and develops a fix
  3. A patched version is released
  4. The vulnerability is publicly disclosed after the fix is available

We ask that you do not publicly disclose the vulnerability until a fix has been released.

Scope

This policy covers:

  • ProxCenter dashboard (frontend)
  • ProxCenter API (backend)
  • Authentication and authorization mechanisms

Out of scope:

  • Proxmox VE itself (report to Proxmox)
  • Third-party dependencies (report to the respective maintainers)

Recognition

We appreciate security researchers who help keep ProxCenter and its users safe. With your permission, we will acknowledge your contribution in the release notes.

There aren’t any published security advisories