Third Party Index

Snapshot 17799

Document
Security advisories
URL
https://vdp.lokalise.com/p/Information-Security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
browser
Size
36375 bytes
SHA-256 (raw)
7cd4eda72b0ddd916fdb6807137f6575d0ace6c2b8bdead95afdbeeffc7b3c91
SHA-256 (normalized text)
33a4e8dcbc02466d635b554579d5c99e1edc5f0d5181119a30413bd511b5ba5e

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Vulnerability Disclosure Policy (VDP)
The safety and security of our customers’ data, and the reliability of our products and services, are of utmost importance to Lokalise. Therefore, we aim to design and make products and services with the highest levels of security and reliability. Despite our best efforts, due to the highly complex and sophisticated nature of our products and services, vulnerabilities and errors may still be present in our products and services.
This policy describes Lokalise’s approach to requesting and receiving reports related to potential vulnerabilities and errors in its products and services from those that interact with such products and services.
Customers, users, researchers, partners and any other person that interacts with Lokalise’s products and services are encouraged to report identified vulnerabilities and errors with such products and services.
The preferred method for contacting Lokalise regarding such vulnerabilities and errors is by using the form present on this page.
Lokalise highly appreciates the efforts made by the reporting party in identifying the vulnerability or error. Reporting of such vulnerabilities and errors will contribute to improving the security and reliability of our product and services.
Please note that supplying your contact information with your report is entirely voluntary and at your discretion. Lokalise will make use of all reports that are submitted; both those submitted anonymously and those with contact information. If you do submit your contact information, Lokalise will only use such information to get in touch with you regarding clarifying the details of your report, if that is necessary. Otherwise, please visit Lokalise’s general privacy policy to see how we respect the privacy of your personal data: https://lokalise.com/privacy-policy
By making a report to Lokalise using the form on this page, or otherwise communicating a report to Lokalise, regarding vulnerabilities and errors, you agree to the following terms:
Lokalise may use your report for any purpose deemed relevant by Lokalise, including without limitation, for the purpose of correcting any vulnerabilities and errors that are reported and that Lokalise deems to exist and to require correction. To the extent that you propose any changes and/or improvements to a Lokalise product or service in your report, you assign to Lokalise all use and ownership rights to such proposals.
You confirm to Lokalise that:
You have not exploited or used in any manner, and will not exploit or use in any manner (other than for the purposes of reporting to Lokalise), the discovered vulnerabilities and/or errors;
You have not engaged, and will not engage, in testing/research of systems with the intention of harming Lokalise, its customers, employees, partners or suppliers;
You have not used, misused, deleted, altered or destroyed, and will not use, misuse, delete, alter or destroy, any data that you have accessed or may be able to access in relation to the vulnerability and/or error discovered;
You have not conducted, and will not conduct, social engineering, spamming, phishing, denial-of-service or resource-exhaustion attacks;
You have not tested, and will not test, the physical security of any property, building, plant or factory of Lokalise;
You have not breached, and will not breach, any applicable laws in connection with your report and your interaction with Lokalise product or service that lead to your report.
You agree not to disclose to any third party any information related to your report, the vulnerabilities and/or errors reported, nor the fact that a vulnerabilities and/or errors has been reported to Lokalise.
Lokalise does not guarantee that you will receive any response from Lokalise related to your report. Lokalise will only contact you regarding your report if Lokalise deems it necessary.
You agree that you are making your report without any expectation or requirement of reward or other benefit, financial or otherwise, for making such report, and without any expectation or requirement that the vulnerabilities and/or errors reported are corrected by Lokalise.
Vulnerability Summary
Report title (250 char maximum)
Product/website concerned (250 char maximum)
Technical details
Bug type
Select a bug type
Endpoint
Vulnerable part
Part name (250 char maximum)
Payload
Technical environment (250 char maximum)
CVE (CVE-YYYY-NNNN)
Impact
CVSS3 Score
CVSS calculator
CVSS metrics
Attack Vector (AV)
Network (N)Adjacent (A)Local (L)Physical (P)
Attack Complexity (AC)
Low (L)High (H)
Privileges Required (PR)
None (N)Low (L)High (H)
User Interaction (UI)
None (N)Required (R)
Scope (S)
Unchanged (U)Changed (C)
Confidentiality (C)
None (N)Low (L)High (H)
Integrity (I)
None (N)Low (L)High (H)
Availability (A)
None (N)Low (L)High (H)
CVSS result
CVSS3 Score: 0. Severity: None.
CVSS3 Score
0
Severity
None
Vulnerability description
Technical description (using Markdown language)
Edit
Preview
Drop or select jpeg or png files (2.0MB/file)
Reporter information
Your name
Your Mail
Your PGP public key
Captcha
I agree with Disclosure policy
By submitting a report, security researcher warrants that the report and any attachments do not violate the intellectual property rights of any third party and the security researcher assigns free of charge to the receiving company who accepts all intellectual property rights.
Mandatory fields