Report a vulnerability
By e-mail, to info@besluitbron.nl. Not on the forum and not in a public issue: a vulnerability posted in public is disclosed to everyone who reads it before anything can be done about it.
What helps
- What the problem is, and what an attacker could do with it.
- How to reproduce it: an address, a request, a sequence of steps.
- The version shown in the top bar, and roughly when the observation was made.
In scope
This installation and everything served under its own address: the public pages, the documentation, the MCP endpoints and the administration console.
Out of scope
- Load testing, denial of service and automated scanning against the source platforms. They are run by other parties, who did not consent to it.
- Findings that follow from a missing header on a page that carries nothing to protect, without a route to an actual consequence.
- Reports produced by a scanner and forwarded unread.
What to expect
Receipt confirmed within 2 working days. After that, an assessment and, where it holds, a fix and a note of the version it lands in.
There is no bug bounty: this is a free service run by a foundation, and paying for reports is not something it can promise.
Please wait with publishing until a fix is available, or until it is clear that none is coming.
The machine-readable version of this page is at /.well-known/security.txt (RFC 9116).