TL;DR: Please do not report security issues publicly, send an email to security@traewelling.de instead. Test on a local installation rather than on traewelling.de where possible. There is no bug bounty programme.
If you have found a security-related bug that could be exploited by others, please do not report it publicly. Instead, send an email to security@traewelling.de.
What this covers
This is about the Träwelling software itself, meaning the code in the repository Traewelling/traewelling.
Third party applications are not covered. They are developed and operated by other people, so issues in them are best reported to them directly.
Please test locally
Träwelling is open source: you can set up the code yourself at any time and try out whatever comes to mind there. Please do that on your own installation rather than on traewelling.de, because real user data lives there.
If a finding only shows up on traewelling.de, please stick to a few rules:
- Only use your own account and your own data.
- Do not access or read other people's accounts or data.
- Do not change or delete anything that is not yours.
- No load or stress testing.
- No social engineering against the team or against other users.
What we need in your report
- Which part is affected? The URL, endpoint or file in the repository
- How can we reproduce it? Step by step is ideal
- What can somebody do with it?
- Did you test locally or on traewelling.de? If there: when, and with which account?
What you can expect from us
We usually see the emails quite quickly and try to reproduce the bug as soon as we can. Träwelling is a side project, though: work, life and all the other things come first, so a detailed answer can take a while.
Publication
Please give us time to fix the issue before you make it public. We will let you know once the fix has been rolled out.
No bug bounty
Please note: we do not run a bug bounty programme and cannot offer any rewards, bounties or payments for reports. Träwelling is a volunteer project, and our budget barely covers the server costs. We are still very grateful for every responsible report.