We support fixing security issues on the following releases:
If you’ve found a security issue in CakeDC Users plugin, please use the following procedure instead of the normal bug reporting system. Instead of using the bug tracker please send an email to security [at] cakedc.com.
For each report, we try to first confirm the vulnerability. Once confirmed, the CakeDC team will take the following actions:
- Acknowledge to the reporter that we’ve received the issue, and are working on a fix. We ask that the reporter keep the issue confidential until we announce it.
- Get a fix/patch prepared.
- Prepare a post describing the vulnerability, and the possible exploits.
- Release new versions of all affected versions.
- Prominently feature the problem in the release announcement
