Third Party Index

Snapshot 49685

Document
Security advisories
URL
https://infuse.com/vdp/
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
static
Size
100369 bytes
SHA-256 (raw)
db78ad02f48e7eed6f35b6fdcf29b7fa5b971c35b359ee4e32e4725ff16acbdb
SHA-256 (normalized text)
818a7b8c6ede3ebd89114f6ae3bd103980b08dacc75902355e90dc3c041ca26e

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Contact Log in
Results for “”
All Matches
Search in title
Search in content
View all results
Home/ INFUSE Vulnerability Disclosure Program/
INFUSE Vulnerability Disclosure Program
1. Program Scope
2. Identifying Vulnerabilities
3. Compensation and Recognition
4. Responsible Disclosure Guidelines
5. Submission Process
6. Legal Safe Harbor
Effective Date: November 20, 2024
Last Updated: November 20, 2024
INFUSE, Inc. is committed to maintaining the security and privacy of our systems, data, and users. We recognize the importance of cybersecurity and welcome responsible vulnerability reporting that can help us enhance our security posture.
Please read this information carefully before conducting any vulnerability research or submitting a report to ensure that your actions align with our guidelines.
1. Program Scope
The scope of this program includes potential vulnerabilities found in INFUSE, Inc.’s cloud-based infrastructure. Since all services and systems are hosted in the cloud, our infrastructure may include but is not limited to the following:
Public-facing web applications and APIs managed by INFUSE, Inc.
Cloud storage solutions that house publicly accessible data (no data extraction should be attempted)
Corporate domains, including INFUSE-linked corporate domains
Infrastructure hosted on third-party cloud platforms
2. Identifying Vulnerabilities
INFUSE, Inc. is interested in reports that demonstrate specific, tangible security impacts. These vulnerabilities include:
Remote Code Execution (RCE)
SQL Injection or equivalent injection vulnerabilities that lead to data access
Cross-site scripting (XSS) that affects user privacy or data
Server-Side Request Forgery (SSRF)
Privilege escalation or unauthorized access to systems
Misconfigured permissions or access controls in cloud storage
Sensitive data exposure, such as PII (personally identifiable information) or financial data
Security misconfigurations in cloud infrastructure that lead to data exposure or unauthorized access
Vulnerabilities of open-source libraries and engines
3. Compensation and Recognition
INFUSE, Inc. values your contributions to security. However, as a matter of policy, INFUSE, Inc. will not provide any compensation or award.
4. Responsible Disclosure Guidelines
To promote responsible disclosure and ensure the safety of our systems:
Do Not Access or Modify Data – Access only information necessary to demonstrate the vulnerability. Do not read, modify, or delete any data that does not belong to you.
Do Not Disrupt – Avoid performing any actions that could disrupt our services, degrade user experience, or risk exposing user data.
Provide Sufficient Detail – Include proof of concept, relevant screenshots, and detailed descriptions of the exploit steps.
Allow Reasonable Time for Response – INFUSE, Inc. aims to acknowledge receipt of submissions within 72 hours and will make every effort to address and remediate reported issues promptly.
5. Submission Process
Contact Information: All submissions should be sent to security@infuse.com with the subject line “Vulnerability Report – [Vulnerability Type].”
Report Template: To facilitate efficient processing, include the following information in your report:
Name and Contact Information
Summary of the vulnerability and potential impact
Detailed steps to reproduce the issue
Any relevant scripts, code, or supporting materials (if applicable)
Severity assessment based on CVSS (if applicable)
Acknowledgment: INFUSE, Inc. will respond to your report within 72 hours to confirm receipt and will work with you as necessary to address any questions about the report.
6. Legal Safe Harbor
INFUSE, Inc. values the role of ethical researchers in maintaining our security standards. Actions conducted in good faith to identify and report vulnerabilities are considered authorized conduct under this program, and we will not take legal action against researchers complying with the program’s terms. However, any activity beyond the scope of this policy may result in legal action.
Thank you for helping us maintain a safe and secure environment at INFUSE!
Select your country
North America
United States – English
Europe
Denmark – English
Finland – English
Ireland – English
Netherlands – English
Norway – English
Poland – English
Sweden – English
United Kingdom – English
Asia
Hong Kong – English
India – English
Indonesia – English
Israel – English
Malaysia – English
Philippines – English
Singapore – English
United Arab Emirates – English
Africa
South Africa – English
Oceania
Australia – English
New Zealand – English