Coordinated Vulnerability Disclosure (CVD) Policy
This policy explains how we receive, evaluate, remediate, and coordinate the disclosure of product security vulnerabilities, as well as the principles that reporters should follow during the research and submission process.
Introduction
We are committed to providing our customers with the information, guidance, and mitigation strategies they need to address product security vulnerabilities in a timely manner. The Product Security Incident Response Team is responsible for coordinating vulnerability response and disclosure, and for advising customers to migrate to supported product versions before the end of the support period.
Handling Vulnerability Reports
Information regarding newly disclosed vulnerabilities should be treated as confidential until it is made public. Once verification is complete, we will coordinate with the product team, third-party vendors, and the reporting party to develop a fix or mitigation plan.
Bug Fixes
- Release a new version of the affected product;
- Provide security patches that can be installed;
- Provide update instructions for third-party components;
- Provide temporary workarounds that can mitigate risks.
Severity and Impact Assessment
| Severity Level | CVSS Base Score |
|---|---|
| Serious | 9.0–10.0 |
| 高 | 7.0–8.9 |
| 中 | 4.0–6.9 |
| 低 | 0.1–3.9 |
External Communication
We provide details on the impact, affected products and versions, CVE/CVSS information, mitigation measures, and necessary reference materials through security advisories, notifications, and informational articles.
How to Report a Security Vulnerability
- Product name, model, and version;
- Operating systems, configurations, and test environments;
- Vulnerability type or CWE;
- Reproducible, step-by-step instructions;
- Proof of Concept and Potential Impact.
Disclaimer
This policy is subject to change based on changes in laws, standards, products, and business operations. Specific customer rights are governed by the applicable contracts, warranties, and support agreements.