脆弱性情報

PGP

Sensitive Email Communications

To ensure confidentiality of email content and to prevent third-parties from acquiring sensitive information, ZUSO ART recommends using the PGP public key encryption below when sending emails to ART@zuso.ai. Thank you.

-----BEGIN PGP PUBLIC KEY BLOCK-----

mQINBGEDe9QBEAC4T/+gAMrsnqELUB6xtTRf3H5A3axAVX30LwRbvuXqmOckgScl
62X9kFPP9GqhclX2NSV4+/LE5++9hIanhni+vKfy+VKmgu5SRnlq8g0Kuds7lFIW
p/nv72PTsFfYzniTFLCsy9A3TNCgeK/Wa4a6XjlnYWtCdpLYQPmjmnQlgK7NUdn3
xItlrMOd4VhLYhcyRQcpsY2Mql7Trr9fCAotGv8nKz1iBeGYgdkYhC8DULdpXYdy
GBrp7dXPRAJr6sPXAt2pgFM8YbyS+XDfHyIBRPuNVNBHrIYZVa14t5V67McqDi6q
XmeXvVDGkuknbOSh6uJ1cQ9eUFeXp/EueeoQ891vJIS+1h2WvKgmjYo9psME82yo
cuYGrmPLzZAOQXtXtE2v8Uty/rRZCz/jNPQjkGbHcRYcXoIcU5X7ulX3Yg8947mi
orJPpFuqTErsXZNaf5ufpJmV7fdrC2FcVnYsoWBWMA64zWWdlNijgU1JiELRGUUB
Pr8ADKZSzaiSiOqgpnIW/sMCTEW5CryLOI5ChxBU1dJU6tZ89YBZRkbG0iFGORXe
5CzR0KuLu7XLHql5sJJndmfllml2Pgw/nCRyhiLf+KqYI+CLNWRaOH8bCNBRHf9L
VSpZp/cSN6GdFWGgyuAZBaJ39vBbIjzfuiHJYVdpPNhV+01Hosuck9+g2wARAQAB
tBZaVVNPIEFSVCA8QVJUQHp1c28uYWk+iQJUBBMBCAA+FiEEqfAZZD9++8e5XHrx
6z4H+PoFHK8FAmEDe9QCGwMFCQeGH1sFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AA
CgkQ6z4H+PoFHK9J6g//WCm5rE3tqcFcc8Srj/r7HLjUcv6ho7Vl2UENpB/jWo/y
R9GrbKatBBQEMmam2pcX/KSTq2VvzweJjCWhfBtvhld8D9fAAsru0YiP5+9b2gHo
yTOolOkNzHYJXQ+6r54xajdDQOFFvvusgfZ5LfZvXELbjpeOW6Cq2erqNzt8uYWN
6ExHIiJCXEWL6W0n1cs8rNm0I/Efilu62L6CvHRhYW3jVgNDeM/9blz/HuHCiv9j
rCiwdhJ1UAK5VAXouQi/KYcG4tC1pNQi41ajtRoXjt4y3duoWOQnHLBKTauB4QsF
qxjvz4KYOochmQHpmHtBAsxT1gL41/8up2HMCkUMZL0hQ8SVRPvaEF+ehbzEQ2dz
Ff2C+yZCfCsjE6+tFfNN9d9i3WWHKu14KQDj780d/57QYGdbyJzH0JCkXpzh30fa
+cdxYoKWu7TjmM4lgc6tk0c2ggWMR/GAxvB6QCdhjFMO0atHVhOY6M1WT15e5juP
TddKzlqguJkigFvQ+jalDRM3WTSagGrYjiE3aqtexTLKiwx8/vHoyrDWPOEeArar
tfTsHeiUB4WuOu8YWm81BU+UStOS9FfucNRf4AiXpZMKSb73EPmhlAm1Lb3QA/Kx
+iQqGfk4OdwwspzhF4/okBtEvnST370RVQukUJHSI62ghssXk6wiMJtPr7lxyVK5
Ag0EYQN71AEQANGJdoT+e7Cy+clU4rvxUmAPUZtGS542BhLczgK04Fg/3Pt3KUBH
SNp0fv8zVjgVqFEuTdQzRZ/oTmu79TeuyfEyO5zvjuxA87HRf4ii/NFHVI1oeFaR
s2FlctrWaxwwabItOpgeFoEVQ7q3lR+0CoC7lbk5K0xZiuv4KMMLztrGyt9+IITf
Sodidg2XG1fE31ewut4Ue+V7Cj5aEQm68SZCYUInsN+XLKm1EgKg6l8lF0UUCzl5
7a8fIDJuCp3ern0bwf+YdTfVmik4blgfVAvJNN5/udQl5woLPeKdncgqbV/FLCMX
rOTyTXOUsQt3+Qkqq/zgTiCRY8KmQQrfQcS9usZzSRjEBxQQUutW+unBn3fjflsT
F54GCTmr6FEtvWeh5ImN00uXw3RFoSENhDG/oTTCguo6oFeq9RJ9Ee/1SBr3d6CQ
W6q1DTIeSQYaicQdFEXiuZkGE82hP/GqIyD4MGDTLXxDKCotTp+tilI5GeUt3e5o
A+Vb6B3NrlsHgbnOqfCTcTjgHXFwiPdBHTTKM//Ooah2JxiNIzj0hvRu7rdJEmR2
gKh3yKGNhEZ6FwO6O/fEsmDCSAw/Gmuad3cYsLWmZ7OMAkfpU/4pAdvjrWY5r+yF
3+beoTc0qn85p1u2x+9pzcH5YRd1+78MBHrr4lc4uVPJSRBp1oJ3KB/BABEBAAGJ
AjwEGAEIACYWIQSp8BlkP377x7lcevHrPgf4+gUcrwUCYQN71AIbDAUJB4YfWwAK
CRDrPgf4+gUcr85RD/9m6CH6kh2dlO8ykbBDk47ZlMYZj4APhV4EqD1gRY/tMacl
yubTcB4LbXBXv/8uUZwnoFdwgyqUACbtxOZ7VMVujH4T9IcYnZTzrGwyK+Wm0vMs
Z8NC8yLWUwPbeqITs/chGXemksNLsUVY+Sf5zP047Aqf4qd+NwONEg8y95sPpHva
C+rbqDOF9OW6UlbCPSLYVekSn671bq6a3o65/AFBHdbJBpZ2DDSkaRpeRFOGd+N6
YkjHjdYBOcvPHYyTYF6kC+AJL1BAgVGx26CsUeZeU949KlilvTpCxFaVNSxEY2Ku
CT8jvQxcbZ0Bv43sbTQ/2HW4Z0WOXAmDkgD7urV0kp+b22wY+vrztXtKMHgEqUDM
Qb8AU16uF/bZqxuZDc4GWdq5hTXhlneXFoELSSgCLMPADWZFvQyaywXeMt4gTO70
zP3j7S2bqRjO5YNmOgnUzOOgnPAsOIlFXqpMzQh1w01BcB8ydgLZaCHrTd6J+I+d
hIq7CJovGtikS6ixzgYN7ng67PDi32Y1NHWlK9RHON3rssMwMYsuoXEmu6W3VZWe
nI184Ks2XnrvQqBLV+gSnyJZj0F7SGYqJatKrj9gyJN5hQ9Jz3CRJ7PkyKAAn3fv
hWdX4tYfQ6e8S8AcpK+CPdK3raA0750ITpIOHg7FYLR6cEXmBDBi+9zikfbP8A==
=U0Wk
-----END PGP PUBLIC KEY BLOCK-----

Disclosure Policy

After ZUSO submits the report to the product vendor, the vulnerability will be kept confidential until the date it can be made public. ZUSO then contacts the relevant product vendor by email with the vulnerability report details.

Initial Report

ZUSO contacts the affected vendor via ART@zuso.ai once we have sufficient vulnerability details on the product, and start calculating the time to fix the vulnerability from the date of contact with the vendor. If the vendor fails to acknowledge ZUSO's initial notification within five business days, ZUSO will rely on an intermediary to try to contact the vendor. ZUSO may issue a public advisory in 15 days if the vendor still fails to respond.

Confirm Vulnerability

Ask the vendor to triage the vulnerability.

Reserve the CVE ID

ZUSO also initiates a CVE ID reservation within five days after having sufficient information on the vulnerability. This step will not reduce the number of repair days.

Public Disclosure

ZUSO attaches great importance to responsible disclosure, so we provide 90 days to give vendors sufficient time to address remediation. Additionally, ZUSO offers vendors a 60-day grace period to extend and make an announcement. The extension depends on the severity of the vulnerability and the remediation progress by the vendor. However, the advisory will be launched to the public 90 days after the initial report.

If ZUSO receives a response from the vendor by the deadline, ZUSO will allow the vendor to extend 60 days to address the vulnerability with a security patch or other appropriate remedy. If the vendor fails to respond by the deadline or fails to provide a reasonable statement that the vulnerability has not been fixed, ZUSO will not extend the disclosure deadline and will issue recommendations to enable community security and protect users.

より強固なセキュリティ防衛線の構築へ