Only the latest release of LDAPWarden receives security updates.
| Version | Supported |
|---|---|
| Latest | ✅ |
| < Latest | ❌ |
We take the security of LDAPWarden seriously. If you discover a security vulnerability, please report it responsibly.
Please do NOT report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, please send an email to security@ldapwarden.org.
To help us triage and prioritize your report, please include as much of the following as possible:
- A description of the vulnerability
- The affected component (e.g., module, function, endpoint)
- Step-by-step instructions to reproduce the issue
- The potential impact of the vulnerability
- Any possible mitigations you have identified
- Your name and affiliation (if you would like to be credited)
- Acknowledgement: We will acknowledge receipt of your report within 72 hours.
- Assessment: We will evaluate the vulnerability and determine its severity and impact.
- Updates: We will keep you informed of our progress toward a fix.
- Disclosure: Once the issue is resolved, we will coordinate with you on responsible disclosure.
- We follow a coordinated disclosure process.
- We ask that you give us a reasonable amount of time to address the issue before any public disclosure.
- We will credit reporters who follow responsible disclosure, unless they prefer to remain anonymous.
- Never commit secrets, credentials, or API keys to the repository.
- Keep dependencies up to date and review them for known vulnerabilities.
- Follow the principle of least privilege in code and configuration.
Thank you for helping keep LDAPWarden and its users safe.