Responsible Disclosure Policy - WoodWing Assets 10 (formerly Swivle) Application
At WoodWing, we consider the security of our systems a top priority. But no matter how much effort we put into system security, there can still be vulnerabilities present.
If you discover a vulnerability, we would like to know about it so we can take steps to address it as quickly as possible. We would like to ask you to help us better protect our clients and our systems.
Please do the following:
- E-mail your findings to team@swivle.com. Encrypt your findings using our PGP key to prevent this critical information from falling into the wrong hands,
- Do not take advantage of the vulnerability or problem you have discovered, for example by downloading more data than necessary to demonstrate the vulnerability or deleting or modifying other people's data,
- Do not reveal the problem to others until it has been resolved,
- Do not use attacks on physical security, social engineering, distributed denial of service, spam or applications of third parties, and
- Do provide sufficient information to reproduce the problem, so we will be able to resolve it as quickly as possible. Usually, the IP address or the URL of the affected system and a description of the vulnerability will be sufficient, but complex vulnerabilities may require further explanation.
What we promise:
- We will respond to your report as soon as possible with our evaluation of the report and an expected resolution date,
- If you have followed the instructions above, we will not take any legal action against you in regard to the report,
- We will handle your report with strict confidentiality, and not pass on your personal details to third parties without your permission,
- We will keep you informed of the progress towards resolving the problem,
- As a token of our gratitude for your assistance, we offer a reward for every report of a security problem that was not yet known to us. The amount of the reward will be determined based on the severity of the leak and the quality of the report. Reports that are not encrypted using our PGP key found above are not eligible for a reward.
We strive to resolve all problems as quickly as possible, and we would like to play an active role in the ultimate publication on the problem after it is resolved.
Out of scope:
Any issue found on the general woodwing.com domain does also not fall under this policy.
WoodWing Assets 10 does not reward trivial vulnerabilities or bugs that cannot be abused. The following are examples of known and accepted vulnerabilities and risks that are outside the scope of the responsible disclosure policy:
- HTTP 404 codes/pages or other HTTP non-200 codes/pages and content spoofing/text injection on these pages.
- Fingerprint version banner disclosure on common/public services.
- Disclosure of known public files or directories or non-sensitive information (e.g. robots.txt).
- Lack of secure/HTTP-only flags on non-sensitive cookies. Examples of sensitive cookies are session cookies and cookies with personally identifiable information. Examples of non-sensitive cookies are loadbalancer preferences and language settings.
- OPTIONS HTTP method enabled.
- Reporting older versions of any software without proof of concept or working exploit.
- Information leaks in metadata.
- Self-XSS and issues exploitable only through Self-XSS.
- CSRF on forms that are available to anonymous users (e.g. the contact form).
- Presence of application or web browser ‘autocomplete’ or ‘save password'.
This Responsible Disclosure Policy was last updated on: March 15, 2024.
PGP key:
mQINBGos+UoBEAC6czlf/yPXAagpQN4aow4VnsX+LnZpeUA5u+CC1evUX+Hm50Oy
6czC4wDeR/4OqkfiRZ/sRITzKyxQ21Ohks+c3eufAifBcbknCitk619iSYkjYJtM
n8szic/YsO3kJRmQYr64MEqslnet+DcDXr6kn21nX1ICzvQbgoA8nnP3Kj1E2LSk
u2Tx8MzBICqIFzi1Aj2cEzUO7QiZuoxFciNH4MdU4GvkmFa/n/NotpBQOk0liwUR
XWkyVRI1cUyBF3TKQa/8OkYXnAewQgWU4fkmAGKH/ZswyTq4fPsDtWbiZa5hvyPF
S9d9hJ4qiKAKP4NjCzUGv2zPLZFYBCIWnQCQGa6IIXWYC/x/Qp+jgIR5/4W9eVfB
cEvqwGOBZQydqhjUUX9fUYk8/G+evL453j20v74KcMW7cIoMBEdP5fXWebFebbpJ
iXNavO88zKVhroSmoJ7+qMDsE2U6T5G1TFg0IEzLxl6uTTp04aNBl90LJIT0wRwN
awhIXznHR/IjWBZIg1b6+ScDv8dRpkQHhNlfw+owaqblSalKcVOS9rR4/ZiPIPA1
c6pzGgswJ1xDEdXSyCvIWWIRO4Z2Wt3lRgFy5OZMViYwg6uDVbhXiPynJU9nuGcr
G+b8vqQAkCyjHQw/tJJYSY7CMEdsAJ1g9caSBdQoeJSMZYTKw5YNQ54++wARAQAB
tB5Xb29kV2luZyA8c3dpdmxlQHdvb2R3aW5nLmNvbT6JAm0EEwEIAFcWIQRnCyy0
tfoC5cuW2fz6sir2pMrphAUCaiz5ShsUgAAAAAAEAA5tYW51MiwyLjUrMS4xMiww
LDMCGwMFCwkIBwICIgIGFQoJCAsCBBYCAwECHgcCF4AACgkQ+rIq9qTK6YSMkxAA
qyohEmCqh0tqX3bIWCPvSdjiRZ5vPak5iQirj2vsXJXadGQiOwIH9OxiMr5g9TPA
So9VDWYCo3p85PLmHjkfPvdKWTaR7lwFg7j+lAgyKBvTGrpzBV8NX8GjuyPTHTTP
EcA7sxSaY/n/qvy4KmvGcL5FYun4PMRBur8FuX4VDswY28bwrGNdCg1Q53lpA5gn
PfJrmro09dpgo5bB7zXoY1Uu5iTq2j8yQPToqAsz0K5oL+5LDEOCK2VMKuza+ZXG
NMhQzndBIFvSaV/WnrDNJYwRzS2a/u7sRfyp+HwXcsrU3/TjrqPNafWbCzsZHm4q
GujqEtxp8cP2y8xVfgncsyou4ezkdC47Bae0lqURa4s0+v/QA/bkicv301Aw6JE6
9z4s14TpdnuxcZssfqcySpBpAlrLY3hPK81wwM4xbvA18lNY63mTno1aNQkbUyuW
NJcLh9O4vFQjCm0Hjw4hJbno37v6+FidAEHC9wmfWiZJwCVLsUI/Mf1YMEI7od1W
WOcgFsclnRS2bnIHI+GEnOvFgIMAcUsUu0WtVcSdtKmiMmYOoF520y2hKrNFMiR6
L3VpLLlDStuMKAyCr1bdjNwTqvpvktksr9ywkF6OMS1z6FzqFANkU07rWGijgBQu
C6SZMdpg4l73cHm114POtW5jyYWq1OrWQTKaguV3Ula5Ag0Eaiz5SgEQAL1Sjb7t
i5rGZ9eJjrM2YrbotxIKcZUk0XlRTCID5oPzW1gA1JzB9MwJFrr/tNNJSYxJtE8h
cBW4seizBIQQBWbqmFgi3H7XQYSl2p/9gfNcy8KdfYvhM2cfBaO/GlJNbiiIRPYu
QdyOwBY9EYZ4WdUufisRebU50Xx0Ey46K2T68weod+f9mqu+C5OupA2Q+AahQtTu
7oWe2SZPjftsY/L/4cMU+7GVMu6BEqg4+f+nnxC5wsnu75loQRcM2OmZVOZAqFhq
SQdVsR+R3XPosAnhi0GOXJWK8jVDHEXK9kkGg+z/dtuYwM0wOOpSgyQDbLbKT8i9
qGicP5x5zvYXKbCTApsa4EUz4pYPXR5VEj9iUfkhG0eSTVePUUfOtmLr/Ekoqoif
vL1MvgZ8amVuL/aieAfyC6lQtFOc3Wt68ZIkVRBRwTeQtkwPBccvfXbERs3+arGh
xdwmix9rCi+ktsodVYqhjKzgi93QK8ExgjKGC04uLcJO7tWlB3IV/1seikrJha90
ZKAYBOIhmvnh/TvcwJz2ln3fp5Yg+5kHsbTVTEqrKdU3dI61BWf3Z4f5V2lD3y02
xAQauxePIh5vWUrxnO/pMiKipYi4LKkig+A0Yq6U4oSsbtEeYkq5Xcc9g9sQ2rQB
jQsSv1/3a3B/CkgCwR/0DIIx04kX8KHtStW5ABEBAAGJAlIEGAEIADwWIQRnCyy0
tfoC5cuW2fz6sir2pMrphAUCaiz5ShsUgAAAAAAEAA5tYW51MiwyLjUrMS4xMiww
LDMCGwwACgkQ+rIq9qTK6YRrfg/+PfTEt9wHUE8ouU5aB9ucTn+N8m7xu4uGUxy0
3+zE7oGtDzIf1H0I/rnoWnV1BsH+lBelmuo6bcVp98qc5egcTYO3/pAqBSEwvZJl
TN3BJIKcRx+8234mAg6+iW0BOgpTl9FIyQ/twJU/ZZshqXuzpT7t+HY4JNutrPh7
qPCXMeD66PDhVLSaleQlgbnKKUy7tf1R6rnoQgvrEsfFW/KTlJj4FnmZuU/Sh/3H
CU4bcmgCzk823hmzVf3YYajIusaDSMvhMn5LR8Zm+UslPpJ3RHUbc9yWBsYh9tyt
FagFJo4ngaqWy7jGekEIxsxr39FSSMYPRRLErSZerGDjnVXo2MRJpPr553nNeu8s
lzDDCZYStqxFYm9PYXOfsMtB8P9bBDdz29BsmEb1f2XyPQrT3o6SDUSjoAFJR2YL
nbxS37oS9bwzwLY7fs6ApsRZ+paU3nSApHzgG88kn3gglJYRIpDpzlTiuqUBC1ck
fQSPblX9fQ0J60mOBEbzLNNsDiYjl1CZeDAmtx+LqFtyAsLEQve3Ghab/pTWj2fo
NtYOLyk5HVeHct+O9n0I99F8G1+m1PFHiBgwRMmYmffaCaFEuJSir9ZGwz8qLZ40
T6JOOjALcXwQO5XY2m4xGOE8PCc8uWbUfMzdcgR6kC+kz5spBw1V/yT40s8ZngqG
jit+4TY=
=+8FN
-----END PGP PUBLIC KEY BLOCK-----
We help you to take charge of your content with our world-class content and information management solutions.
Receive our Newsletter?