Security updates and patches are actively applied to the following versions of VER:
| Version | Supported |
|---|---|
| 1.3.x | ✅ |
| 1.2.x | ✅ |
| < 1.2.0 | ❌ |
The security of VER and our users' credentials is of paramount importance.
If you discover a security vulnerability or potential credential leak:
- Do not disclose it publicly on GitHub issues, pull requests, or discussions.
- Please report the vulnerability privately via GitHub Security Advisories.
- If GitHub Private Advisories are unavailable, contact the project maintainer directly.
- Description of the vulnerability and its potential security impact.
- Detailed steps or proof of concept to reproduce the issue.
- Affected operating system, desktop environment, or protocol connectors (e.g. FreeRDP, TigerVNC, OpenSSH).
- Any suggested mitigations or fixes.
- Acknowledgment: You will receive an acknowledgment of your report within 48 hours.
- Assessment & Fix: A patch will be developed, tested, and released promptly.
- Public Disclosure: Coordinated public disclosure will follow once a patch has been released.