Most SPX installations run locally on-prem, but more and more SPX instances are becoming virtualized in-the-cloud. We are aware of some vulnerabilities and welcome you to tell us if you find one.
If you find a vulnerability you have two options:
- Use the Security Advisory feature (preferred), or
- Email [email protected]
In your report,
- describe the issue
- showcase how it can be used
- let us know if you would like to be credited in the README file and with what name?
We will try reply to your email within 72 hours. If the issue is confirmed, we will release a patch as soon as possible depending on complexity but typically within a few days, in the next binary release at the latest.