Skip to content

Security: Free-IAM/freeiam

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability, please report it privately by emailing the maintainers at:

security@freeiam.org

Please do not report security issues via GitHub Issues or other public channels.

When reporting, please include:

  • A detailed description of the vulnerability
  • Steps to reproduce or a proof-of-concept, if possible
  • The version of the software affected
  • Your contact information for follow-up questions

Common Vulnerabilities and Exposures (CVE)

If a security vulnerability is confirmed and deemed significant, a CVE identifier may be requested and assigned to publicly track the issue. This helps ensure transparency and allows users and tools to easily identify and address known vulnerabilities.


Security Updates

We take security seriously and will respond promptly to reports.

Fixes will be prioritized and released as soon as possible. We will announce security releases via our usual channels.


Recommendations

  • Always keep your installation up to date with the latest security patches.
  • Use strong authentication credentials for LDAP bind accounts.
  • Restrict access to your LDAP servers and management interfaces.
  • Regularly audit your access control policies (ACLs).

Dependencies

This project strives to minimize its dependencies to reduce the attack surface and improve security.

We regularly monitor and update dependencies for vulnerabilities.

Please notify us if you find any insecure dependencies.


Thank You

Thank you for helping us keep the project secure!


There aren't any published security advisories