Security#

Vulnerability Disclosure Policy#

At Qblox, the security of our products and our customers’ data is our top priority. We highly value the work of the independent security research community and are committed to working with you to verify and address any potential vulnerabilities in our systems. If you believe you have discovered a security vulnerability in one of our products or systems, we encourage you to notify us immediately. We ask that you follow this Coordinated Vulnerability Disclosure (CVD) policy to ensure a safe, secure, and timely resolution.

How to Report a Vulnerability#

Please report all potential vulnerabilities directly to our security team by emailing: security@qblox.com. To help us understand and resolve the issue quickly, please include the following information in your report:

  • The Product/System: The exact product (model, configuration and firmware version for hardware products, software version for our software products) where the vulnerability exists.

  • The Vulnerability: A clear description of the issue and the potential impact.

  • Steps to Reproduce: Instructions allowing our engineers to recreate the issue.

  • Your Contact Information: So we can follow up with you (you may remain anonymous if you prefer).

Security Advisories#

When vulnerabilities are identified, we publish Security Advisories here. Below you will find our archive, organized per year, with information about the vulnerabilities found, remediation instructions, patches, mitigations and workarounds.