Skip to content

Security: PaloAltoNetworks/pan-stix

Security

SECURITY.md

Security

Palo Alto Networks takes the security of our software products and services seriously, which includes all source code repositories managed through our GitHub organizations.

If you believe you have found a security vulnerability in any Palo Alto Networks-owned repository, please report it to us as described below.

Reporting Security Issues

Please do not report security vulnerabilities through public GitHub issues.

Instead, please report them to Palo Alto Networks PSIRT at https://security.paloaltonetworks.com/report.

If you prefer to submit via email, send your report to psirt@paloaltonetworks.com. If possible, encrypt your message with our PGP key; please download it from the security.paloaltonetworks.com.

Please include the requested information listed below (as much as you can provide) to help us better understand the nature and scope of the possible issue:

  • Description: Provide a detailed description of the vulnerability, including the affected repository or package and its version, if applicable.
  • Reproduction Steps: Clearly outline the steps required to reproduce the vulnerability. This will assist us in understanding and validating the issue effectively.
  • Impact: Explain the potential impact and risks associated with the vulnerability, including any potential data exposure, system compromise, or other adverse consequences.
  • Supporting Material: Whenever possible, please provide any additional material that helps demonstrate or clarify the vulnerability. This can include proof-of-concept code, network captures, screenshots, or any other relevant information.

This information will help us triage your report more quickly.

Policy

Palo Alto Networks follows the principle of Responsible Vulnerability Disclosure.

There aren’t any published security advisories