Security Bugfix Service Level Agreement
We attempt to meet the following timeframes for fixing security issues.
- Critical severity bugs (CVSS v2 score >= 8, CVSS v3 score >= 9) should be fixed in product within 4 weeks of being reported.
- High severity bugs (CVSS v2 score >= 6, CVSS v3 score >= 7) should be fixed in product within 6 weeks of being reported.
- Medium severity bugs (CVSS v2 score >= 3, CVSS v3 score >= 4) should be fixed in product within 8 weeks of being reported.
Critical vulnerabilities
When a Critical security vulnerability is discovered Appbox.ai will do all of the following:
- Inform affected clients about this vulnerability & suggest a workaround if possible.
- Inform relevant vendors about this vulnerability & keep them informed about the incident.
- Issue a new, fixed release for the current version of the affected product as soon as possible.
Non-critical vulnerabilities
When a security issue of a High, Medium or Low severity is discovered, we will include the fix in the next scheduled maintenance release.
If not set to automatically upgrade, you should upgrade your installation in order to fix the vulnerability.