This page provides information about the correct and necessary actions to take when security concerns about Percona software arise. Some information applies to Percona customers, some to non-customers using Percona software, and some to both groups.
Percona open-source software merges upstream code releases. To allow Percona time to integrate enhancements and perform quality assurance testing, delays may occur after an upstream release to the equivalent Percona release.
Percona naming conventions follow upstream. For example, Percona Software version 1.2.3-55.0 breaks down into 1.2.3 being the upstream version the product is equivalent to, with -55.0 being the Percona-specific revisions and enhancements against the upstream version.
Percona operates a Responsible Disclosure program for legitimate reported issues that affect Percona or potentially affect Percona customers or Percona software users.
Scope
Note: exclusions below.
We are no longer accepting reports that include the following:
Percona requests that your report includes at a minimum the following details for consideration:
Percona’s Security Team will make every effort to work with security researchers, provided they comply with the terms above.
Reports received that do not detail the issue or make an attempt to do so may be rejected outright.
The Percona Security Team will make every effort to work with researchers to thoroughly understand the issue being reported, and agree on a timeframe for a fix where applicable.
Percona implements automated email filtering to limit the delivery of spam, malware, etc. Please ensure when emailing your report to include a valid email address to respond to, a subject line, and email body content to ensure delivery.
The following testing activities are prohibited under the Responsible Disclosure and Bug Bounty program. Any testing that includes any of the following will result in action being taken to restrict such activity and/or refer to law enforcement agencies where appropriate:
Should you have a legitimate test case that might include one of the above, please contact [email protected] detailing your proposed test, expected outcome, and proposed timelines.
Percona is grateful for any contributions made to the Responsible Disclosure program at Percona.
Percona at this time does not offer an official bounty program. In cases where a report is thought to warrant some reward, the Percona Security and Managerial teams, at their discretion, may provide rewards ranging from swag to monetary compensation where deemed appropriate.
Reporting a privacy concern to Percona
Percona is committed to protecting your privacy. You can read our Privacy Policy, including your choices regarding the collection, use, and sharing of your data.