
脆弱性情報
PGP
Sensitive Email Communications
To ensure confidentiality of email content and to prevent third-parties from acquiring sensitive information, ZUSO ART recommends using the PGP public key encryption below when sending emails to ART@zuso.ai. Thank you.
Disclosure Policy
After ZUSO submits the report to the product vendor, the vulnerability will be kept confidential until the date it can be made public. ZUSO then contacts the relevant product vendor by email with the vulnerability report details.
Initial Report
ZUSO contacts the affected vendor via ART@zuso.ai once we have sufficient vulnerability details on the product, and start calculating the time to fix the vulnerability from the date of contact with the vendor. If the vendor fails to acknowledge ZUSO's initial notification within five business days, ZUSO will rely on an intermediary to try to contact the vendor. ZUSO may issue a public advisory in 15 days if the vendor still fails to respond.
Confirm Vulnerability
Ask the vendor to triage the vulnerability.
Reserve the CVE ID
ZUSO also initiates a CVE ID reservation within five days after having sufficient information on the vulnerability. This step will not reduce the number of repair days.
Public Disclosure
ZUSO attaches great importance to responsible disclosure, so we provide 90 days to give vendors sufficient time to address remediation. Additionally, ZUSO offers vendors a 60-day grace period to extend and make an announcement. The extension depends on the severity of the vulnerability and the remediation progress by the vendor. However, the advisory will be launched to the public 90 days after the initial report.
If ZUSO receives a response from the vendor by the deadline, ZUSO will allow the vendor to extend 60 days to address the vulnerability with a security patch or other appropriate remedy. If the vendor fails to respond by the deadline or fails to provide a reasonable statement that the vulnerability has not been fixed, ZUSO will not extend the disclosure deadline and will issue recommendations to enable community security and protect users.