BesluitBron 1.4.4-23 Status Sign in

Report a vulnerability

By e-mail, to info@besluitbron.nl. Not on the forum and not in a public issue: a vulnerability posted in public is disclosed to everyone who reads it before anything can be done about it.

What helps

  • What the problem is, and what an attacker could do with it.
  • How to reproduce it: an address, a request, a sequence of steps.
  • The version shown in the top bar, and roughly when the observation was made.

In scope

This installation and everything served under its own address: the public pages, the documentation, the MCP endpoints and the administration console.

Out of scope

  • Load testing, denial of service and automated scanning against the source platforms. They are run by other parties, who did not consent to it.
  • Findings that follow from a missing header on a page that carries nothing to protect, without a route to an actual consequence.
  • Reports produced by a scanner and forwarded unread.

What to expect

Receipt confirmed within 2 working days. After that, an assessment and, where it holds, a fix and a note of the version it lands in.

There is no bug bounty: this is a free service run by a foundation, and paying for reports is not something it can promise.

Please wait with publishing until a fix is available, or until it is clear that none is coming.

The machine-readable version of this page is at /.well-known/security.txt (RFC 9116).