We take the security of Zuup Auth Gateway seriously. We currently provide security updates for the following versions of the project:
| Version | Supported |
|---|---|
| 2.8x | ✅ |
| < 2.8x | ❌ |
If you discover a security vulnerability within the Zuup Auth Gateway or its underlying proxy infrastructure, please DO NOT open a public issue on GitHub.
Instead, please send an email to jagrit@zuup.dev with a detailed description of the vulnerability, including:
- Type of issue (e.g., buffer overflow, SQL injection, cross-site scripting, bypass).
- Steps to reproduce the issue, including any relevant code or payloads.
- Impact of the vulnerability.
- You should receive a confirmation of receipt within 48 hours.
- We will review the vulnerability and determine the severity.
- We will work with you to understand and resolve the issue.
- Once the issue is resolved, we will publish a security patch and credit you for the discovery (if desired).
Thank you for helping keep the Zuup ecosystem safe!