Skip to content

Security: redsunservers/LoadoutBugTracker

SECURITY.md

Security Policy

Scope

Reports are considered in-scope if they involve the following:

  • Red Sun Loadout
  • Red Sun Forums
  • In-Game Loadout Core plugins
  • Red Sun Exclusive (RSX) sub-plugins
  • Red Sun Gamemodes

Additionally, reports will be considered in-scope if they involve a public plugin known to run on our Game Servers which exposes a significant vulnerability e.g. RCE, Arbitary input etc.

Reports are NOT considered in scope for the following services:

  • Red Sun FastDL
  • Third Party Platforms (e.g. Discord)

Reporting a Vulnerability

Use this section to tell people how to report a vulnerability.

Please include details of:

  • The type of issue found
  • Steps on how to replicate the issue
  • Evidence of the issue (pictures, video etc. We ask that any data exfiltrated is anonymised and deleted after verification, and not spread to unauthorized parties.).
  • Proof of Concept tools/exploits used
  • Suggested remediation (optional)
  • Name to be credited under (optional)

Once a vulnerability has been found and patched, we will assess the scope and severity of the disclosed vulnerability. On confirmation of the information, we may choose to offer you a bug bounty.

DO NOT "BUG BEG" AKA "BOUNTY BEG". NO REPLICATION/PoC, NO BOUNTY. BUG BEGGERS ARE IGNORED.

There aren't any published security advisories